Boosting D3FEND: Ontological analysis and recommendations

In Formal Ontology in Information Systems. Nieuwe Hemweg, The Netherlands: IOS Press (forthcoming)
  Copy   BIBTEX

Abstract

Formal Ontology is a discipline whose business is to develop formal theories about general aspects of reality such as identity, dependence, parthood, truth-making, causality, etc. A foundational ontology is a specific consistent set of these ontological theories that support activities such as domain analysis, conceptual clarification, and meaning negotiation. A (well-founded) core ontology specifies, under a foundational ontology, the central concepts and relations of a given domain. Foundational and core ontologies can be seen as ontology engineering frameworks to systematically address the laborious task of building large (more specific) domain ontologies. However, both in research and industry, it is common that ontologies as computational artifacts are built without the aid of any framework of this kind, often yielding modeling mistakes and representation gaps. In this paper, we analyze a case in the domain of cybersecurity, namely, the case of D3FEND — an OWL knowledge graph of cybersecurity countermeasure techniques proposed by the MITRE Corporation. Based on the Reference Ontology for Security Engineering (ROSE), a core ontology of the security domain founded in the Unified Founda-tional Ontology (UFO), our investigation reveals a number of semantic issues and opportunities for improvement in D3FEND, including missing concepts, semantic overload of terms, and lacking constraints that cause an under-specification of the model. As a result of our ontological analysis, we propose several suggestions for the appropriate redesign of D3FEND to overcome those issues.

Links

PhilArchive



    Upload a copy of this work     Papers currently archived: 92,347

External links

  • This entry has no external links. Add one.
Setup an account with your affiliations in order to access resources via your University's proxy server

Through your library

Similar books and articles

Ontological Analysis and Redesign of Security Modeling in ArchiMate.Ítalo Oliveira, Tiago Prince Sales, João Paulo A. Almeida, Riccardo Baratella, Mattia Fumagalli & Giancarlo Guizzardi - 2022 - In Ítalo Oliveira, Tiago Prince Sales, João Paulo A. Almeida, Riccardo Baratella, Mattia Fumagalli & Giancarlo Guizzardi (eds.), The Practice of Enterprise Modeling - 15th IFIP WG 8.1 Working Conference, PoEM 2022. Springer. pp. 82-98.
Scoping the ethical principles of cybersecurity fear appeals.Marc Dupuis & Karen Renaud - 2020 - Ethics and Information Technology 23 (3):265-284.
A process-ontological account of work.Baris Parkan - 2004 - Axiomathes 14 (1-3):219-235.

Analytics

Added to PP
2023-05-05

Downloads
0

6 months
0

Historical graph of downloads

Sorry, there are not enough data points to plot this chart.
How can I increase my downloads?

Author Profiles

Riccardo Baratella
University of Genoa
Ítalo Oliveira
Free University of Bozen-Bolzano
Tiago Prince Sales
Free University of Bozen-Bolzano

Citations of this work

No citations found.

Add more citations

References found in this work

No references found.

Add more references