4.1 Article

Sustainable Risk Identification Using Formal Ontologies

期刊

ALGORITHMS
卷 15, 期 9, 页码 -

出版社

MDPI
DOI: 10.3390/a15090316

关键词

formal ontology; risk identification; cybersecurity; vulnerability

向作者/读者索取更多资源

The cyber threat landscape is dynamic, and continuous monitoring and contextualisation are needed for risk identification. Manual risk identification hinders consideration of emerging threats. OnToRisk offers an automated method to identify and understand cyber risks, integrating information from various sources using formal ontology definitions.
The cyber threat landscape is highly dynamic, posing a significant risk to the operations of systems and organisations. An organisation should, therefore, continuously monitor for new threats and properly contextualise them to identify and manage the resulting risks. Risk identification is typically performed manually, relying on the integration of information from various systems as well as subject matter expert knowledge. This manual risk identification hinders the systematic consideration of new, emerging threats. This paper describes a novel method to promote automated cyber risk identification: OnToRisk. This artificial intelligence method integrates information from various sources using formal ontology definitions, and then relies on these definitions to robustly frame cybersecurity threats and provide risk-related insights. We describe a successful case study implementation of the method to frame the threat from a newly disclosed vulnerability and identify its induced organisational risk. The case study is representative of common and widespread real-life challenges, and, therefore, showcases the feasibility of using OnToRisk to sustainably identify new risks. Further applications may contribute to establishing OnToRisk as a comprehensive, disciplined mechanism for risk identification.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.1
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据