Title :
Enhanced Vulnerability Ontology for Information Risk Assessment and Dependability Management
Author :
Aime, Marco D. ; Guasconi, Fabio
Author_Institution :
Dip. di Autom. e Inf., Politec. di Torino, Torino, Italy
Abstract :
Security vulnerabilities play an increasing role within dependability procedures for information systems. However, traditional vulnerability models present several general shortcomings when matched with today requirements. To overcome these limits, we propose a vulnerability ontology based on three main enhancements: deeper integration with system asset ontology, better modelling of cause-effect relationships, and deeper integration with dependability control ontology.
Keywords :
cause-effect analysis; information systems; ontologies (artificial intelligence); risk management; security of data; cause-effect relationship; information risk assessment; information system dependability; system asset ontology; vulnerability ontology; Context; Information systems; Ontologies; Risk management; Security; Software; Information risk assessment; Information system dependability; Vulnerability ontology;
Conference_Titel :
Dependability (DEPEND), 2010 Third International Conference on
Conference_Location :
Venice
Print_ISBN :
978-1-4244-7530-8
DOI :
10.1109/DEPEND.2010.22