作者: R. Riesco , V. A. Villagrá
DOI: 10.1007/S10207-019-00433-2
关键词: Information exchange 、 De facto standard 、 Semantic Web Rule Language 、 Ontology language 、 Computer security 、 Risk management framework 、 Semantic reasoner 、 Management process 、 Computer science 、 Risk management
摘要: One of the most important goals in an organization is to have risks under acceptance level along time. All organizations are exposed real-time security threats that could impact on their risk exposure levels harming entire organization, customers and reputation. New emerging techniques, tactics procedures (TTP) which remain undetected, complexity decentralization assets, great number vulnerabilities proportional new type devices (IoT) or still high false positives, only some examples real for any organization. Risk management frameworks not integrated automated with near (NRT) risk-related cybersecurity threat intelligence (CTI) information. The contribution this paper architecture based Web Ontology Language (OWL), a semantic reasoner use Semantic Rule (SWRL) approach Dynamic Assessment Management (DRA/DRM) framework at all (operational, tactic strategic). To enable such dynamic, NRT more realistic assessment processes, we created version STIX™v2.0 cyber as it becoming de facto standard structured information exchange. We selected international leading demonstrate dynamic ways support decision making while being attack. reasoners be our ideal partners fight against having control time, that, they need understand data. Our proposal uses unprecedented mix standards cover DRM ensure easier adoption by users.