论文标题
采用本体驱动的方法进行过程感知风险传播的方法
Towards an Ontology-Driven Approach for Process-Aware Risk Propagation
论文作者
论文摘要
网络物理系统的快速开发产生了对普通风险方法的需求不断增长,尤其是考虑到物理和数字组件如何影响系统本身的过程。在风险分析和管理中,风险传播是一种中心技术,它允许计算系统内风险的级联效应并支持降低风险活动。但是,一个开放的挑战是设计一种过程感知风险传播解决方案,该解决方案可用于评估不同水平的抽象,会计参与者,过程,物理数字对象及其相互关系的风险的影响。为了应对这一挑战,我们提出了一种基于两个主要组成部分的过程感知风险传播方法:i。支持语义Web技术(SWT)和基于语义的智能系统的典型功能的本体论,代表具有具有不同抽象级别的过程和对象的系统,以及II。计算给定系统中风险传播的方法。我们在概念验证工具中实施了方法,该工具在网络安全域中得到了验证和证明。
The rapid development of cyber-physical systems creates an increasing demand for a general approach to risk, especially considering how physical and digital components affect the processes of the system itself. In risk analytics and management, risk propagation is a central technique, which allows the calculation of the cascading effect of risk within a system and supports risk mitigation activities. However, one open challenge is to devise a process-aware risk propagation solution that can be used to assess the impact of risk at different levels of abstraction, accounting for actors, processes, physical-digital objects, and their interrelations. To address this challenge, we propose a process-aware risk propagation approach that builds on two main components: i. an ontology, which supports functionalities typical of Semantic Web technologies (SWT), and semantics-based intelligent systems, representing a system with processes and objects having different levels of abstraction, and ii. a method to calculate the propagation of risk within the given system. We implemented our approach in a proof-of-concept tool, which was validated and demonstrated in the cybersecurity domain.