Ontology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications
Title | Ontology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications |
Publication Type | Conference Paper |
Year of Publication | 2019 |
Authors | Aman, W., Khan, F. |
Conference Name | 2019 IEEE 8th Global Conference on Consumer Electronics (GCCE) |
Keywords | application configurations, application security, Automation, Business, context-aware security assessment automation, critical infrastructure, Dynamic Application Security Testing, Measurement, Metrics, metrics testing, Ontologies, ontologies (artificial intelligence), Ontology, ontology-based dynamic security assessment automation, ontology-based security model, pubcrawl, quantifiable security assessment process, security aptitude, security assessment architecture, security metrics, security of data, security testing, Standards, Testing, Tools, ubiquitous computing, virtualisation, virtualization |
Abstract | Several assessment techniques and methodologies exist to analyze the security of an application dynamically. However, they either are focused on a particular product or are mainly concerned about the assessment process rather than the product's security confidence. Most crucially, they tend to assess the security of a target application as a standalone artifact without assessing its host infrastructure. Such attempts can undervalue the overall security posture since the infrastructure becomes crucial when it hosts a critical application. We present an ontology-based security model that aims to provide the necessary knowledge, including network settings, application configurations, testing techniques and tools, and security metrics to evaluate the security aptitude of a critical application in the context of its hosting infrastructure. The objective is to integrate the current good practices and standards in security testing and virtualization to furnish an on-demand and test-ready virtual target infrastructure to execute the critical application and to initiate a context-aware and quantifiable security assessment process in an automated manner. Furthermore, we present a security assessment architecture to reflect on how the ontology can be integrated into a standard process. |
DOI | 10.1109/GCCE46687.2019.9015599 |
Citation Key | aman_ontology-based_2019 |
- ontology-based security model
- Virtualization
- virtualisation
- ubiquitous computing
- tools
- testing
- standards
- security testing
- security of data
- Security Metrics
- security assessment architecture
- security aptitude
- quantifiable security assessment process
- pubcrawl
- application configurations
- ontology-based dynamic security assessment automation
- Ontology
- ontologies (artificial intelligence)
- Ontologies
- Metrics
- metrics testing
- Measurement
- Dynamic Application Security Testing
- critical infrastructure
- context-aware security assessment automation
- Business
- automation
- application security