Defender-centric conceptual cyber exposure ontology for adaptive cyber risk assessment

4Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A major gap in cybersecurity studies, especially as it relates to cyber risk, is the lack of comprehensive formal knowledge representation, and often a limited view, mainly based on abstract security concepts with limited context. Additionally, much of the focus is on the attack and the attacker, and a more complete view of risk assessment has been inhibited by the lack of knowledge from the defender landscape, especially in the matter of the impact and performance of compensating controls. In this study, we will start by defining a conceptual ontology that integrates concepts that model all of cybersecurity entities. We will then present an adaptive risk reasoning approach with a particular focus on defender activities. The main purpose is to provide a more complete view, from the defender perspective, that bridges the gap between risk assessment theories and practical cybersecurity operations in real-world deployments.

Cite

CITATION STYLE

APA

Aouad, L., & Asghar, M. R. (2020). Defender-centric conceptual cyber exposure ontology for adaptive cyber risk assessment. In ICETE 2020 - Proceedings of the 17th International Joint Conference on e-Business and Telecommunications (Vol. 3, pp. 580–586). SciTePress. https://doi.org/10.5220/0009826205800586

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free