Critique Popular Risk Assessment and Management Procedures
Semantic Risk Assessment for Cybersecurity
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz Poznan University of Economics, Poznan, Poland [email protected] [email protected] [email protected] Abstract: Cybersecurity is in essence a function of risk reduction for the organization. Due to the rapid evolvement and wide diversity of technologies, it is important that risks will be managed in a way that is capable of handling much wider and diversified knowledge while reducing the increasing costs of such effort. There is a variety of methods for risk assessment but it is common for them to consider threats and improve security by taking countermeasures. Due to constraints of budget and time together with the rapid evolvement of risks (threats), knowledgeable prioritization is important. In this paper we present a semantic approach to the handling of a "fabric of knowledge" in the form of a model and ontology of the cyberse- curity body of knowledge. Such a model may serve as a cybersecurity framework, managing the knowledge in a way that enables sharing of the knowledge while bridging terminology gaps and automatic processing of the data. It makes use of machine understanding and automatic reasoning. Several aspects of the cybersecurity body of knowledge are examined, presenting a semantic way of handling them, together with the benefits of handling them semantically. These aspects cover the cybersecurity body of knowledge extensively, culminating to risk assessment based on knowledge that is wider and more up to date while also enable automatic reasoning. The automatic reasoning may assist in better processing of the vast amount of new knowledge that is constantly added to this body of knowledge. Such reasoning may also be part of the knowledge, and also shared the rest of the knowledge. This paper proposes semantic approach for risk management. The CORAS risk assessment and the CVSS risk scoring methods are used to exemplify semantic representation of the risk assess- ment and scoring sub domains, respectively. A model is presented, advantages and limitations are discussed. Keywords: cyber security, semantic web technology, risk management, risk assessment
1. Introduction As our world becomes more and more digital, the dependency on information technology grows and the need of risk management regarding cybersecurity becomes more and more imminent. In our view, risk assessment is the basis for risk management, providing determination of risks as well as their severity and likelihood. Risk management also includes possible mitigations and the handling of risks meant to reduce either the likelihood or severity of a realization of risk, reducing the potential damage that is usually considered as an economical one (although the damage might not be economical but rather political, medical, vandal, etc.). Risk assessment is usually considered an organizational process, but we refer only to the knowledge aspect of it, not to the se- quence of operations or the teams that are involved. In this paper we propose to leverage semantic technology to manage cybersecurity. We refer mainly to risk assessment using semantic web technology, by taking a well-known risk assessment method and presenting a model how to handle it semantically by semantic web technologies. We also refer to a well-known cybersecurity scoring method because due to its numerical nature it might be seen as a difficulty to semantic, so we present a model for it, too. Having based our model for those two cases, we view semantic web technology as advanta- geous for cybersecurity risk assessment. The advantages and limitations of the semantic approach for cyberse- curity are discussed. The rest of this paper is organized as follows: the rest of this chapter introduces the risk assessment and scoring methods as well as the semantic web which will be later considered to handle risk assessment and scoring. In chapter 2 we delve deeper to the CORAS and CVSS that are chosen to represent risk assessment and scoring, respectively. Chapter 3 presents our proposal to handle CORAS and CVSS semantically and chapter 4 provides conclusions and limitations of our approach, in brief. Chapter 5 includes the references.
2. Related work
2.1 The semantic web
Semantic web technology provides means to handle information: organizing knowledge chunks, relating them, sharing and accessing the knowledge. It also provides means to gain further knowledge through machine rea- soning – drawing conclusions based on rules. The semantic web aims to provide means to structure a web of
513
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
interlinked data, while adding meaning to the data. This enables processing of data at a higher level of “under- standing” by machines. Semantic web technology refers to the concepts rather than the terms and provides vocabulary building features [Berners-lee et al. 2001]. This semantic bridging, like the entire semantic web technology, applies to machines as well as humans. It enables separate contents to be connected, even if they are not known in advance to each party. Reasoning may be applied to newly connected contents, not defined by a common predetermined schema or by a mapping between shared schemes. Relationships may also be added on the fly, not necessarily defined up-front. The capability of automatic reasoning is a keystone of semantic technology. Indeed, it is the reasoning that can cope with new entities and varying terms. The technology to serve this vision is comprised of three components (“the stack”): XML [Feigenbaum et al. 2007], adding structure tags to documents. RDF [Cyganiak Richard et al. 2014], adding meaning to the data in the form of a triple: thing – property – value (of the property) or subject-verb-object. The third component is ontologies (OWL) in the form of taxonomy and inference rules. Formal RDF Model. RDF is “a framework for representing information in the web” [Cyganiak Richard et al. 2014]. The information is represented as collection of triples, each in the form of subject-verb/predicate-object. It can be depicted as a directed graph. The graph nature of RDF provides inherent flexibility for addition of information, through addition of entities (subjects or objects) and their relationships (predicates) with other entities. Such triples or graphs can be chained to connect pieces of knowledge and enable inference of new data. Ontologies. For the semantic web, ontology is the mean to represent knowledge by capturing the concepts of the domain and their inter-relationships. In [Berners-lee et al. 2001] it is referred to as “a taxonomy and a set of inference rules”. The semantic web uses ontologies to bridge between resources of knowledge by specifying concepts for accurate meaning and by deducing further knowledge. Being accessible over the web, providing meaning and inferencing – ontologies enable sharing of knowledge. Machine inference may enable acquiring new facts about threats and reasoning of derived risks. Knowledge Sharing. Ontology is a representation of knowledge, and sharing ontologies supports sharing of knowledge. The knowledge can be shared by machines and enables them to process information that would otherwise require manual intervention. Knowledge sharing is a major benefit of ontologies [Gruber 1993]. The entire semantic web technology is also aimed for sharing of knowledge (among other goals) [Shadbolt et al. 2006]. It enables bridging over differences in terminology by referring to the meaning. It enables reasoning knowledge based on the relationships between concepts. Semantic web technology also enables organizing the knowledge in classes and subclasses. This capability lends itself to capture and handle “families” of threats, which many times have lot of derivatives based on technology (e.g. based on versions of operating systems). The family attributes of threats is valuable information [Brown et al. 2015]. Rules, Reasoning and Compliance. While ontologies are about classes and the relationships among the classes, subclasses and their instances, rules and reasoning are about discovering and generating new relationships based on existing ones [World Wide Web Consortium (W3C) 2008]. Rules guide the reasoning of consequences of explicit knowledge. Actually rules and reasoning create new data from existing data through adding relation- ships, leveraging either explicit data or machine “understanding” of meaning. Rules and reasoning provide a powerful mechanism that enables the addition of new explicit knowledge to be leveraged to addition of further knowledge, which is not added but is rather reasoned. Such a mechanism is of great value in domains which are highly dynamic, artefact driven, with ongoing addition of artefacts and relationships. In domains with dominant sub-classing reasoning may be more effective as it can draw on the very belonging of a concept to a certain class or super-class to apply relevant reasoning. In domains that need sharing of knowledge, reasoning rules may be shared as part of the knowledge.
2.2 Risk management
Risk management has several definitions [R. Shirey 2007]. In [CNSS 2010] risk management is defined as a meas- ure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function
514
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
of 1) the adverse impacts that would arise if the circumstance or event occurs; and 2) the likelihood of occur- rence. Risk management as pertains to information security is a comprehensive process that requires organizations to: frame risk (i.e., establish the context for risk-based decisions), assess risk, respond to risk once determined, and monitor risk [NIST 2012]. Risk assessment is the process of identifying, estimating, and prioritizing information security risks. Assessing risk requires the careful analysis of threat and vulnerability information [NIST 2011]. In our view, risks may be defined as the gap between the threats and the defensive capabilities of the organization, representing dangers to which the organization is exposed (for this purpose insurance may be considered as a means of defence). According to [NIST 2011], risk assessment involves a process, a risk model with risk factors and the relationship among them, an assessment approach (e.g., quantitative, qualitative, or semi-qualitative) specifying the range of values those risk factors can assume and an analysis approach (e.g., threat-oriented, asset/impact-oriented, or vulnerability-oriented) used to describe the problem space. The risk assessment pro- cess entails sharing of risk-related information. The sharing of information of risk assessment and of risk in gen- eral is of high importance. Efforts like The SCAP [Quinn et al. 2010], STIX [Barnum 2014], MAEC [Pecification et al. 2013], TAXII [Davidson et al. 2014] indicate the importance of information sharing. AURUM [Ekelhart et al. 2009] is an ontology based methodology meant to support the NIST SP 800-30 [ISO/IEC 2007] risk management standard. It provides comprehensive capabilities of receiving provided data into the system’s ontological framework. It is focused on making the work with NIST SP 800-30 interactive using screen forms and going through the process defined by the standard, rather than providing a knowledge resource be- yond the knowledge included in the NIST SP 800-30 standard. Although ontology based, the basic approach is extending a single ontological resource rather than automation, reasoning, incorporation of resources and se- mantic bridging and as aimed in this work. The ontological model is not provided.
2.3 Risk assessment methods
Risk assessment involves means like methodologies, frameworks, ranking and scoring systems. Methods have been developed to handle risks, usually based on risk factors as they are identified and weighted by human judgment. Comparisons of methods for risk assessment may be found in works like [ENISA 2006a], [Bornman, Labuschagne 2004], [Rashid et al. 2012], and [Vorster, Labuschagne 2005]. A common distinction is between qualitative methods and quantitative ones. Quantitative methods use numerical terms (yet determined by hu- man judgment), while qualitative methods use non-numerical terms. In [Rashid et al. 2012], qualitative methods are considered better for today's complex systems, as quantitative one may not be able to model complex risk scenarios. In [ENISA 2006b], the concepts of qualitative and quantitative methods are introduced but such a distinction for the surveyed methods is not provided. Qualitative methods also fit better to semantic representation since they are less about calculations and more about influences of various properties – which may be represented as relationships and reasoning. Also, cyber- security is primarily approached from a qualitative perspective [Meulen 2015]. Therefore we focus on a qualita- tive approach to show that risk assessment can be expressed semantically and represent the knowledge that is relevant for risk assessment. Following the choice of a qualitative approach over the quantitative one, we came to choose the particular method. In this work the methods presented in [Vorster, Labuschagne 2005] were examined, as they were cho- sen for being well documented. From among the methodologies considered in [Vorster, Labuschagne 2005], OCTAVE [James Woody 2003] and CORAS [Lund et al. 2011] are considered qualitative. Also, in [Rashid et al. 2012], the authors survey risk analysis methods and provide ranking of methods by references. They rank Octave first with 11 out of 14 references, and CRAMM and CORAS follow with 7 and 6 references, respectively. We chose CORAS to demonstrate semantic representation of risk analysis discipline for the following reasons. First, OCTAVE [James Woody 2003] is an organization-level approach to cyber risk assessment, focusing on operations rather than on knowledge issues on which we focus in this work. Second, CORAS is based on a UML [Omg 2011] model providing objects and relations and well defined syntax [Solhaug, Stølen 2013], while OCTAVE is not fo- cused on entities and relations but rather on organization bodies and activities. Being model-based, CORAS is better defined in terms of having well identified entities and relations, to the extent of providing translation to textual syntax and then to English [Dahl et al. 2007]. Having the model entities and relations, it is easier to define
515
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
a semantic model for CORAS – as provided in this work. By [den Braber et al. 2006], CORAS is the only model based methods for security analyses.
2.4 CORAS
The CORAS approach is based on the ISO 31000 standard for risk management. It includes three components: a language, a tool which is basically a graph editor and a method which defines the organizational process. In this work we refer mainly to the language component, as we focus on the knowledge aspect of cybersecurity, rather than the organization process or tools involved. The CORAS language is diagrammatic. It uses diagrams to rep- resent the knowledge acquired through the organizational process. The diagrams are as follows: Asset diagrams - describe the focus of the analysis, Threat diagrams - describe scenarios which may cause harm to the assets, Risk diagrams - summarize the risks presented in threat diagrams, Treatment diagrams - add proposed treat- ments to threat diagrams, Treatment overview diagrams - add proposed treatments to risk diagrams. The enti- ties that comprise the diagrams are: threat (of three kinds: non-human, human-accidental, human-deliberate), vulnerability, threat-scenario, unwanted-incident, asset. Several other risk management methods are referred to in [Eloff et al. 1993].
2.5 Scoring and CVSS
Metric and scoring systems have been defined to assist in prioritization of defensive efforts. In order to demon- strate how the semantic approach may handle such scoring, two known scoring systems where considered: CVSS [NIST n.d.] and DREAD [Owasp 2010]. CVSS was chosen to exemplify semantic representation of scoring, since it is more developed and documented. CVSS is a widely accepted industry standard for assessing the se- verity of IT vulnerability relative to other vulnerabilities, enabling prioritization of risk mitigation. It is one of several metrics proposed. CVSS prioritizes vulnerabilities by collecting human judgments of fixed criteria, which rank various aspects of a designated vulnerability and calculate numerical value used to prioritize vulnerability handling. It takes into account aspects that change over time, such as whether or not there is a patch for this vulnerability, and aspects that change from one environment to another such as collateral damage potential.
3. Semantic approach for risk assessment The following sub-sections demonstrate our model through semantic representation for CORAS and for CVSS. In our view, the semantic approach and our model can represent risk assessment knowledge in a way that provides further qualities over the common way.
3.1 Semantic representation of CORAS
CORAS produces charts based on human brainstorming. Such brainstorming cannot be conducted frequently, yet cybersecurity is a very dynamic domain and poses new threats at a rapid pace. The threats also require human knowledge as well as data repositories to consider threats. This calls for ongoing process of acquiring new data and process risks. We propose to apply CORAS semantically, enabling automation of such ongoing process based on machine reasoning and inclusion of further web knowledge repositories. In this work we ex- press the CORAS diagrams using semantic web modelling. This way, further capabilities may be gained: integra- tion with other knowledge resources and new knowledge provided by reasoning. For example, such reasoning may integrate the target of analysis (the organization’s IT) and provide an up to date reasoning of relevant threats and countermeasures based on updates to the target of analysis. Semantic bridging between resources produced by different teams and jargons is also enabled. The CORAS language is comprised of basic “building blocks” noted in diagrams as vertices, and “relations” noted as edges. We address one of them as an example for the semantic representation that may be used. We argue that the CORAS diagrams may be expressed as semantic concepts and relationships, so semantic representation may include the CORAS knowledge while it can also be extended with further knowledge and utilize reasoning. In [Dahl et al. 2007], a method is presented how to automatically convert the diagrams to text and structured semantics is provided for this purpose. This conversion is modular, and is done relation by relation, vertex by vertex. We will elaborate this using the threat diagram as an example. Threat diagram basic building blocks are: deliberate, accidental, and non-human threat, vulnerability, threat scenario, unwanted incident (likelihood), and asset. Threat diagram relations: initiate (may be annotated with
516
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
likelihood), impact (may in some cases be annotated with a consequence). Figure 1: CORAS risk diagram example exemplifies CORAS risk diagrams, as appeared in [Hogganvik, Stølen 2006].
Figure 1: CORAS risk diagram example
The CORAS threat diagram brought here is represented in our model as depicted in Figure 2: Semantic repre- sentation of risk diagram. The relationships of threats to risks are “pose-risk” and the relationships of risks to assets are “endangers”. The conversion could be one-to-one for the nodes and connections.
Figure 2: Semantic representation of risk diagram. Source: Own work
For semantic modelling we propose to conduct such a process, but make each step create ontology concepts and relationships, rather than English statements. The vertices may be represented as concepts and the edges may be represented as the relationships that connect the vertices by various relationships. Super-classing may be used to model the common properties of threats: deliberate, accidental, and non-human threat may all be sub-classes of a threat. The risks are expressed by defining several types of the concept: risk-minor, risk-medium and risk-major that are sub-classes of risk. Other designs may also do. In case of a numerical value (e.g. likelihood * severity) – pre-prepared tables may be used, or language built-ins may serve for the calculation. Such conver- sion may even be done automatically. The building blocks and relations are closed groups for each diagram, and can be converted to concepts and relationships in a modular manner. The diagrams are aspects of the same problem space with some overlapping such as in the case of “overview” diagrams (e.g. treatment overview dia- gram, asset overview diagram). While the authors propose automatic conversion to English sentences for humans, we propose to convert it automatically to RDF representation for machines. This can be done for further diagrams, providing further as- pects of the problem space. We believe that semantic web technology may provide further dimension to the CORAS method, in addition to the graphic and textual dimensions. CORAS uses brainstorming to identify risks, and may benefit from an inclusion of resources into the process: resources of threats, threat intelligence and more resources that may be provided by a semantic model. This may happen through addressing questions like: “what threats and vulnerabilities are known for the assets that we have” – and having up-to-date response based on common resources. The semantic dimension may provide integration with wider, pre-existing knowledge and provide automatic reasoning pointing out risks and suggesting counter measures, etc.
3.2 Semantic representation of CVSS
The “one size fits all” approach of metric methods may not fit to particular circumstances. CVSS is used as a standard risk metric for vulnerabilities and is widely recommended as a patch-prioritization metric, but
517
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
[Massacci 2013] reports that “not only CVSS generally performs poorly as a metric for vulnerability remediation, but that monitoring the cybercrime black markets may result in up to 20% more effective patching policies”. This is indeed an effort to incorporate further knowledge (in this case – about attack resources) into risk assess- ment. In [Zalewski et al. 2013], it is noted that ”the basic problem with both CVSS and risk calculation methods, how- ever, is that they have been developed with vulnerabilities of typical internet applications in mind, and are not oriented towards cyber-physical systems”. Also, this prioritization does not take into account considerations like: in case when vulnerabilities prioritized as second and third might enable a greater risk than the one prioritized first, or the cost & complexity of mitigating them is lower – one may prefer to handle them before handling the first. The existence of some counter measure in the organization may also influence prioritization, e.g. if there is already an advanced firewall installed, one may prefer to re-configure it in order to handle some vulnerability that is prioritized a little lower than another vulnerability that requires purchasing and installing new gear. Also, intelligence about a specific threat (e.g. a campaign planned) may lead to prioritize specific vulnerability higher than CVSS would rank it. CVSS seems to reflect a vendor's perspective that does not consider the enterprise’s context, more than an enterprise view point. Such cases imply that numerical scoring and fixed formulas may not address some considerations that might be dealt with by semantic technology. Although we favor qualitative handling of risks over standard quantitative scoring “measurement”, an excerpt of our semantic representation of CVSS for our model is provided in Figure 3: Semantic representation of CVSS base metrics.
Figure 3: Semantic representation of CVSS base metrics. Source: Own work
518
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
4. Conclusions and future research Following the cases with CORAS risk assessment method and with CVSS risk scoring method, we view the se- mantic web as capable of handling the risk assessment and risk scoring subdomains, while providing further benefits. Such benefits are automatic handling of new data using reasoning, sharing knowledge and inclusion of common knowledge repositories and bridging terminology gaps. The semantic approach is limited by the nature of data that can be handled. Streaming media like video and audio cannot be handled unless accompanied by some metadata that can be processed semantically. There are open knowledge repositories on the Web that can be handled semantically, but video/audio resources would require preparation of metadata. We believe that semantic approach lends itself well to the cybersecurity domain and not only to risk assessment and scoring, and we are researching the semantic approach to cybersecurity in a wider context.
References Barnum, S., 2014. STIX Whitepaper. Available at: http://stixproject.github.io/getting-started/whitepaper [Accessed
December 23, 2015]. Berners-lee, T.I.M., Hendler, J. & Lassila, O.R.A., 2001. The Semantic Web. Scientific American, 284(May), pp.1–4. Available
at: http://www.nature.com/doifinder/10.1038/scientificamerican0501-34. Bornman, W.G. & Labuschagne, L., 2004. A comparative framework for evaluating information security risk management
methods. Information Security South Africa Conference. den Braber, F. et al., 2006. The CORAS model-based method for security risk analysis, Available at:
http://scholar.google.com/scholar?hl=en&btnG=Search&q=intitle:The+CORAS+Model- based+Method+for+Security+Risk+Analysis#0.
Brown, S., Gommers, J. & Serrano, O., 2015. From Cyber Security Information Sharing to Threat Management. Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security, pp.43–49.
CNSS, 2010. National Information Assurance (IA) Glossary. The National Security Systems Instruction, (4009), p.103. Available at: http://www.cnss.gov/Assets/pdf/cnssi_4009.pdf.
Cyganiak Richard, D., Wood David, 3Round Stones & Lanthaler Markus, G.U. of T., 2014. RDF 1.1 Concepts and Abstract Syntax. W3C, pp.1–2. Available at: https://www.w3.org/TR/2014/REC-rdf11-concepts-20140225/ [Accessed October 7, 2016].
Dahl, H.E.I., Hogganvik, I. & Stølen, K., 2007. Structured semantics for the CORAS security risk modelling language. Preproceedings of the 2nd International Workshop on Interoperability solutions on Trust Security Policies and QoS for Enhanced Enterprise Systems ISTSPQ07, (September), pp.79–92. Available at: http://folk.uio.no/ketils/kst/Articles/2007.IS-TSPQ-preprint.pdf.
Davidson, M., Schmidt, C. & Connolly, J., 2014. TAXII Whitepaper _ TAXII Project Documentation. MITRE. Available at: http://taxiiproject.github.io/getting-started/whitepaper/ [Accessed August 31, 2016].
Ekelhart, a., Fenz, S. & Neubauer, T., 2009. AURUM: A Framework for Information Security Risk Management. 2009 42nd Hawaii International Conference on System Sciences, (September 2008), pp.1–10.
Eloff, J.H.P., Labuschagne, L. & Badenhorst, K.P., 1993. A comparative framework for risk analysis methods. Computers and Security, 12(6), pp.597–603.
ENISA, 2006a. Inventory of risk assessment and risk management methods, ENISA, 2006b. Risk Management : Implementation principles and Inventories for Risk Management / Risk Assessment
methods and tools, Available at: https://www.enisa.europa.eu/activities/risk-management/current-risk/risk- management-inventory/files/deliverables/risk-management-principles-and-inventories-for-risk-management-risk- assessment-methods-and-tools.
Feigenbaum, L. et al., 2007. The semantic web in action. Scientific American, (December), pp.90–97. Available at: http://www.nature.com/scientificamerican/journal/v297/n6/full/scientificamerican1207-90.html [Accessed April 17, 2014].
Gruber, T., 1993. Toward principles for the design of ontologies used for knowledge sharing. International journal of human-computer studies, pp.907–928. Available at: http://www.sciencedirect.com/science/article/pii/S1071581985710816 [Accessed April 23, 2014].
Hogganvik, I. & Stølen, K., 2006. A graphical approach to risk identification, motivated by empirical investigations. Model Driven Engineering Languages and Systems, pp.574–588. Available at: http://www.springerlink.com/index/w61261v834167681.pdf.
ISO/IEC, 2007. ISO/IEC 27005:2007, Information technology - Security techniques - Information security risk management. James Woody, C.A.C.D.A.S., 2003. Introduction to the OCTAVE Approach, Available at:
http://www.itgovernanceusa.com/files/Octave.pdf. Lund, M.S., Solhaug, B. & Stølen, K., 2011. Model-driven risk analysis: The CORAS approach,
519
Adiel Aviad, Krzysztof Wecel and Witold Abramowicz
Massacci, L.A. and W.S. and F., 2013. Quantitative assessment of risk reduction with black market monitoring. Mastercard; Visa, 1997. SET Secure Electronic Transaction Specification Book 2: Programmer’s Guide. Business, pp.1–22.
Available at: http://www.mastercard.com/set/set.htm,. Meulen, N. Van Der, 2015. Investing in Cybersecurity. Available at: https://www.wodc.nl/images/2551-volledige-
tekst_tcm44-602708.pdf. NIST, 2012. Guide for Conducting Risk Assessments, Available at:
http://scholar.google.com/scholar?hl=en&btnG=Search&q=intitle:NIST+Special+Publication+800-30#0. NIST, 2011. Managing Information Security Risk Organization, Mission, and Information System View, Available at:
http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf. NIST, NVD - CVSS. Web page. Available at: https://nvd.nist.gov/cvss.cfm [Accessed September 29, 2015]. Omg, 2011. UML Infrastructure Specification, v2.4.1. Omg, (August), p.34. Available at:
http://www.omg.org/spec/UML/2.4.1/Infrastructure/PDF/. Owasp, 2010. Threat Risk Modeling - OWASP. , pp.1–10. Available at:
https://www.owasp.org/index.php/Threat_Risk_Modeling [Accessed September 2, 2016]. Pecification, V.E.S. et al., 2013. The Maec Language. Available at: https://maecproject.github.io/. Quinn, S. et al., 2010. Guide to Adopting and Using the Security Content Automation Protocol ( SCAP ) Version 1.0, R. Shirey, 2007. RFC 4949 - Internet Security Glossary, Version 2. , (2), pp.1–365. Available at: https://www.rfc-
editor.org/rfc/pdfrfc/rfc4949.txt.pdf. Rashid, R.A., Behnia, A. & Chaudhry, J.A., 2012. A Survey of Information Security Risk Analysis Methods. The Smart
Computing Review, 2(1), pp.79–94. Shadbolt, N., Berners-Lee, T. & Hall, W., 2006. The Semantic Web Revisited. IEEE Intelligent Systems, 21(3), pp.96–101.
Available at: http://ieeexplore.ieee.org/lpdocs/epic03/wrapper.htm?arnumber=1637364. Solhaug, B. & Stølen, K., 2013. The CORAS Language – why it is designed the way it is. In E. & F. (Eds) Deodatis, ed. Safety,
Reliability, Risk and Life-Cycle Performance of Structures & Infrastructures. Vorster, A. & Labuschagne, L.E.S., 2005. A Framework for Comparing Different Information Security Risk Analysis
Methodologies. In Proceedings of the 2005 annual research conference of the South African institute of computer scientists and information technologists on IT research in developing countries (SAICSIT 2005), (July 2005), pp.95–103.
World Wide Web Consortium (W3C), 2008. Inference - W3C. Available at: http://www.w3.org/standards/semanticweb/inference [Accessed October 29, 2016].
Zalewski, J. et al., 2013. Threat modeling for security assessment in cyberphysical systems. Proceedings of the Eighth Annual Cyber Security and Information Intelligence Research Workshop on - CSIIRW ’13, p.1. Available at: http://dl.acm.org/citation.cfm?doid=2459976.2459987.
520
Copyright of Proceedings of the International Conference on Cyber Warfare & Security is the property of Academic Conferences & Publishing International Ltd. and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.