201. Design and Implementation of a Comprehensive Insider Threat Ontology
- Author
-
Justin Purl, James D. Lee, Abbas K. Zaidi, and Frank L. Greitzer
- Subjects
Knowledge management ,business.industry ,Computer science ,Insider threat ,020206 networking & telecommunications ,02 engineering and technology ,Ontology language ,Ontology (information science) ,Knowledge base ,0202 electrical engineering, electronic engineering, information engineering ,General Earth and Planetary Sciences ,020201 artificial intelligence & image processing ,business ,Threat assessment ,General Environmental Science - Abstract
We describe the development and envisioned use case applications of a comprehensive insider threat ontology—“Sociotechnical and Organizational Factors for Insider Threat” (SOFIT)—that comprises more than 300 indicators of technical, behavioral, and organizational factors. Requirements, design, and engineering development for the Web Ontology Language (OWL) implementation of the SOFIT knowledge base are reviewed; additional relationships among constructs are defined that extend the representation beyond a simple taxonomic hierarchy and that enable inferences for qualitative and quantitative threat assessment. We show how queries may be constructed to support these inferences and threat assessments. Several major application concepts are reviewed to show how the ontology may be used by the insider threat research and operational communities. To this end, the SOFIT knowledge base may be shared with stakeholders to advance research and practice for proactive insider threat mitigation.
- Published
- 2019
- Full Text
- View/download PDF