Automated expert system knowledge base development method for information security risk analysis

13Citations
Citations of this article
55Readers
Mendeley users who have this article in their library.

Abstract

Information security risk analysis is a compulsory requirement both from the side of regulating documents and information security management decision making process. Some researchers propose using expert systems (ES) for process automation, but this approach requires the creation of a high-quality knowledge base. A knowledge base can be formed both from expert knowledge or information collected from other sources of information. The problem of such approach is that experts or good quality knowledge sources are expensive. In this paper we propose the problem solution by providing an automated ES knowledge base development method. The method proposed is novel since unlike other methods it does not integrate ontology directly but utilizes automated transformation of existing information security ontology elements into ES rules: The Web Ontology Rule Language (OWL RL) subset of ontology is segregated into Resource Description Framework (RDF) triplets, that are transformed into Rule Interchange Format (RIF); RIF rules are converted into Java Expert System Shell (JESS) knowledge base rules. The experiments performed have shown the principal method applicability. The created knowledge base was later verified by performing comparative risk analysis in a sample company.

Cite

CITATION STYLE

APA

Vitkus, D., Steckevicius, Z., Goranin, N., Kalibatiene, D., & Cenys, A. (2019). Automated expert system knowledge base development method for information security risk analysis. International Journal of Computers, Communications and Control, 14(6), 743–758. https://doi.org/10.15837/ijccc.2019.6.3668

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free