Visible to the public Ontology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications

TitleOntology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications
Publication TypeConference Paper
Year of Publication2019
AuthorsAman, W., Khan, F.
Conference Name2019 IEEE 8th Global Conference on Consumer Electronics (GCCE)
Keywordsapplication configurations, application security, Automation, Business, context-aware security assessment automation, critical infrastructure, Dynamic Application Security Testing, Measurement, Metrics, metrics testing, Ontologies, ontologies (artificial intelligence), Ontology, ontology-based dynamic security assessment automation, ontology-based security model, pubcrawl, quantifiable security assessment process, security aptitude, security assessment architecture, security metrics, security of data, security testing, Standards, Testing, Tools, ubiquitous computing, virtualisation, virtualization
Abstract

Several assessment techniques and methodologies exist to analyze the security of an application dynamically. However, they either are focused on a particular product or are mainly concerned about the assessment process rather than the product's security confidence. Most crucially, they tend to assess the security of a target application as a standalone artifact without assessing its host infrastructure. Such attempts can undervalue the overall security posture since the infrastructure becomes crucial when it hosts a critical application. We present an ontology-based security model that aims to provide the necessary knowledge, including network settings, application configurations, testing techniques and tools, and security metrics to evaluate the security aptitude of a critical application in the context of its hosting infrastructure. The objective is to integrate the current good practices and standards in security testing and virtualization to furnish an on-demand and test-ready virtual target infrastructure to execute the critical application and to initiate a context-aware and quantifiable security assessment process in an automated manner. Furthermore, we present a security assessment architecture to reflect on how the ontology can be integrated into a standard process.

DOI10.1109/GCCE46687.2019.9015599
Citation Keyaman_ontology-based_2019