Abstract
A major gap in cybersecurity studies, especially as it relates to cyber risk, is the lack of comprehensive formal knowledge representation, and often a limited view, mainly based on abstract security concepts with limited context. Additionally, much of the focus is on the attack and the attacker, and a more complete view of risk assessment has been inhibited by the lack of knowledge from the defender landscape, especially in the matter of the impact and performance of compensating controls. In this study, we will start by defining a conceptual ontology that integrates concepts that model all of cybersecurity entities. We will then present an adaptive risk reasoning approach with a particular focus on defender activities. The main purpose is to provide a more complete view, from the defender perspective, that bridges the gap between risk assessment theories and practical cybersecurity operations in real-world deployments.
Author supplied keywords
Cite
CITATION STYLE
Aouad, L., & Asghar, M. R. (2020). Defender-centric conceptual cyber exposure ontology for adaptive cyber risk assessment. In ICETE 2020 - Proceedings of the 17th International Joint Conference on e-Business and Telecommunications (Vol. 3, pp. 580–586). SciTePress. https://doi.org/10.5220/0009826205800586
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.