Ontology-Based Business Knowledge for Simulating Threats to Corporate Assets

  • Ekelhart A
  • Fenz S
  • Klemen M
  • et al.
N/ACitations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

We propose a security ontology, to provide a solid base for an applicable and holistic IT-Security approach for SMEs, enabling low-cost threat analysis. Based on the taxonomy of computer security and dependability by Landwehr [ALRL04] and the threat classification according to Peltier [Pel0l], a heavy-weight ontology can be used to organize and systematically structure knowledge on threats, safeguards, and assets. The ontology is used in an organization to capture business knowledge required for and created during a security risk analysis where instances of concepts are added to the ontology to allow the simulation of different attack and disaster scenarios. Each scenario can be replayed with a different protection profile as to evaluate the effectiveness and the cost/benefit ratio of individual safeguards.

Cite

CITATION STYLE

APA

Ekelhart, A., Fenz, S., Klemen, M. D., Tjoa, A. M., & Weippl, E. R. (2006). Ontology-Based Business Knowledge for Simulating Threats to Corporate Assets (pp. 37–48). https://doi.org/10.1007/11944935_4

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free