Swinburne
Browse

An ontology framework for managing security attacks and defences in component based software systems

Download (413.32 kB)
conference contribution
posted on 2024-07-09, 18:06 authored by Artem Vorobiev, Jun HanJun Han, Nargiza Bekmamedova
Software systems become increasingly distributed, involving many independent and collaborating components working towards achieving system goals. At the same time, security attacks on these systems have also grown being more sophisticated and are quite difficult to identify and mitigate, in particular including distributed attacks. In this paper, we argue that one way to detect and resist against such attacks is through the collaboration of a system's constituent components. To achieve collaborative defense in a distributed component-based system, a common basis (vocabulary) is needed for the components to communicate and work with each other in detecting attacks and devising countermeasures. We adopt an ontological approach to establishing such a common base and introduce ontologies concerning security attacks and defenses. The ontologies specify the security concepts and their relationships in a way understandable to both humans and software agents. We use a case study involving Mitnick attacks to demonstrate how system components use the ontologies to detect and counter attacks.

History

Available versions

PDF (Published version)

ISBN

769531008

ISSN

1530-0803

Journal title

Proceedings of the Australian Software Engineering Conference, ASWEC

Conference name

The Australian Software Engineering Conference, ASWEC

Pagination

9 pp

Publisher

IEEE

Copyright statement

Copyright © 2008 IEEE. The published version is reproduced in accordance with the copyright policy of the publisher. Personal use of this material is permitted. However, permission to reprint/republish this material for advertising or promotional purposes or for creating new collective works for resale or redistribution to servers or lists, or to reuse any copyrighted component of this work in other works must be obtained from the IEEE.

Language

eng

Usage metrics

    Publications

    Categories

    No categories selected

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC