Ontology-based dynamic and context-aware security assessment automation for critical applications

Waqas Aman, Fazlullah Khan

Research output: Chapter in Book/Conference proceedingConference contributionpeer-review

5 Citations (Scopus)

Abstract

Several assessment techniques and methodologies exist to analyze the security of an application dynamically. However, they either are focused on a particular product or are mainly concerned about the assessment process rather than the product's security confidence. Most crucially, they tend to assess the security of a target application as a standalone artifact without assessing its host infrastructure. Such attempts can undervalue the overall security posture since the infrastructure becomes crucial when it hosts a critical application. We present an ontology-based security model that aims to provide the necessary knowledge, including network settings, application configurations, testing techniques and tools, and security metrics to evaluate the security aptitude of a critical application in the context of its hosting infrastructure. The objective is to integrate the current good practices and standards in security testing and virtualization to furnish an on-demand and test-ready virtual target infrastructure to execute the critical application and to initiate a context-aware and quantifiable security assessment process in an automated manner. Furthermore, we present a security assessment architecture to reflect on how the ontology can be integrated into a standard process.

Original languageEnglish
Title of host publication2019 IEEE 8th Global Conference on Consumer Electronics, GCCE 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages644-647
Number of pages4
ISBN (Electronic)9781728135755
DOIs
Publication statusPublished - Oct 2019
Externally publishedYes
Event8th IEEE Global Conference on Consumer Electronics, GCCE 2019 - Osaka, Japan
Duration: 15 Oct 201918 Oct 2019

Publication series

Name2019 IEEE 8th Global Conference on Consumer Electronics, GCCE 2019

Conference

Conference8th IEEE Global Conference on Consumer Electronics, GCCE 2019
Country/TerritoryJapan
CityOsaka
Period15/10/1918/10/19

Keywords

  • Automation
  • Critical Infrastructure
  • Dynamic Application Security Testing
  • Ontology
  • Virtualization

ASJC Scopus subject areas

  • Instrumentation
  • Artificial Intelligence
  • Computer Networks and Communications
  • Computer Science Applications
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Ontology-based dynamic and context-aware security assessment automation for critical applications'. Together they form a unique fingerprint.

Cite this