首页> 外文OA文献 >SERSCIS: Semantic Modelling of Dynamic, Multi-Stakeholder Systems
【2h】

SERSCIS: Semantic Modelling of Dynamic, Multi-Stakeholder Systems

机译:sERsCIs:动态多利益相关方系统的语义建模

摘要

This paper describes a novel approach to semantic system and security modelling developed in the SERSCIS project. The approach is designed to address dynamic multistakeholder systems that are composed from services at run-time. This presents several challenges for security risk modelling and management that are not well addressed by previous work. The biggest challenge is the fact that at design-time one only knows the structure but not the composition of the system, forcing an abstract modelling approach to be used. The SERSCIS approach deals with this by defining a set of OWL classes describing generic system assets, threats and security controls and the relationships between them. This dependability model captures security expertise concerning the types of threats that can arise in general and the controls that can be used to address them. An abstract system model can then be created using OWL subclasses, to capture the types of assets and their relationships in a specific system, but still without specifying how many assets, where they are deployed or what security controls they have. The resulting models can be used as inputs to run-time semantic monitoring tools, where the knowledge encoded in the abstract system model is used to automatically determine system threat activity and system vulnerabilities. The approach was validated in an Airport Collaborative Decision-Making scenario.
机译:本文描述了在SERSCIS项目中开发的一种新颖的语义系统和安全建模方法。该方法旨在解决运行时由服务组成的动态多利益相关方系统。这为安全风险建模和管理提出了一些以前的工作未能很好解决的挑战。最大的挑战是这样一个事实:在设计时,人们只知道系统的结构,但不知道系统的组成,因此不得不采用抽象的建模方法。 SERSCIS方法通过定义一组描述通用系统资产,威胁和安全控制以及它们之间的关系的OWL类来解决此问题。此可靠性模型捕获有关一般可能出现的威胁类型以及可用来解决这些威胁的控制措施的安全专业知识。然后可以使用OWL子类创建抽象的系统模型,以捕获特定系统中资产的类型及其关系,但仍未指定多少资产,将其部署在何处或拥有哪些安全控制。生成的模型可以用作运行时语义监视工具的输入,在运行时语义监视工具中,抽象系统模型中编码的知识用于自动确定系统威胁活动和系统漏洞。该方法在机场协作决策场景中得到了验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号