Ontology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications

Waqas Aman, Fazlullah Khan

Research output: Chapter in Book/Report/Conference proceedingConference contribution

5 Citations (Scopus)

Abstract

Several assessment techniques and methodologies exist to analyze the security of an application dynamically. However, they either are focused on a particular product or are mainly concerned about the assessment process rather than the product's security confidence. Most crucially, they tend to assess the security of a target application as a standalone artifact without assessing its host infrastructure. Such attempts can undervalue the overall security posture since the infrastructure becomes crucial when it hosts a critical application. We present an ontology-based security model that aims to provide the necessary knowledge, including network settings, application configurations, testing techniques and tools, and security metrics to evaluate the security aptitude of a critical application in the context of its hosting infrastructure. The objective is to integrate the current good practices and standards in security testing and virtualization to furnish an on-demand and test-ready virtual target infrastructure to execute the critical application and to initiate a context-aware and quantifiable security assessment process in an automated manner. Furthermore, we present a security assessment architecture to reflect on how the ontology can be integrated into a standard process.

Original languageUndefined/Unknown
Title of host publicationIEEE 8th Global Conference on Consumer Electronics, GCCE 2019, Osaka, Japan, October 15-18, 2019
PublisherIEEE
Pages644-647
Number of pages4
ISBN (Electronic)9781728135755
DOIs
Publication statusPublished - 2019
Event8th IEEE Global Conference on Consumer Electronics, GCCE 2019 - Osaka, Japan
Duration: Oct 15 2019Oct 18 2019

Publication series

Name2019 IEEE 8th Global Conference on Consumer Electronics, GCCE 2019

Conference

Conference8th IEEE Global Conference on Consumer Electronics, GCCE 2019
Country/TerritoryJapan
CityOsaka
Period10/15/1910/18/19

Keywords

  • Automation
  • Critical Infrastructure
  • Dynamic Application Security Testing
  • Ontology
  • Virtualization

ASJC Scopus subject areas

  • Artificial Intelligence
  • Instrumentation
  • Electrical and Electronic Engineering
  • Computer Networks and Communications
  • Computer Science Applications

Cite this