Security ontologies: Improving quantitative risk analysis

75Citations
Citations of this article
113Readers
Mendeley users who have this article in their library.
Get full text

Abstract

IT-security has become a much diversified field and small and medium sized enterprises (SMEs), in particular, do not have the financial ability to implement a holistic IT-security approach. We thus propose a security ontology, to provide a solid base for an applicable and holistic IT-security approach for SMEs, enabling low-cost risk management and threat analysis. Based on the taxonomy of computer security and dependability by Landwehr [1], a heavy-weight ontology can be used to organize and systematically structure knowledge on threats, safeguards, and assets. Using this ontology, each threat scenario can be simulated with a different protection profile as to evaluate the effectiveness and the cost/benefit ratio of individual safeguards. © 2007 IEEE.

Cite

CITATION STYLE

APA

Ekelhart, A., Fenz, S., Klemen, M., & Weippl, E. (2007). Security ontologies: Improving quantitative risk analysis. In Proceedings of the Annual Hawaii International Conference on System Sciences. https://doi.org/10.1109/HICSS.2007.478

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free