Semantic Potential of existing Security Advisory Standards
نویسندگان
چکیده
New discoveries made on a nearly daily basis and the constantly growing amount of vulnerabilities in software products have led to the distribution of great numbers of vendor dependent vulnerability information over various channels such as mailing lists and RSS (Really Simple Syndication) feeds. However, the format of these messages presents a major problem as it lacks standardized, semantic information, resulting in very time-intensive, expensive, and error-prone processing due to the necessary human involvement. Recent developments in the field of IT security have increased the need for a sound semantic security advisory standard that allows for automatic processing of relevant security advisories in a more precise and timely manner. This would reduce pressure on organizations trying to keep their complex infrastructures secure and up-to-date by complying with standards, such as Basel II and local legislations. This paper conducts an evaluation of existing security advisory standards to identify usable semantic standards, which enable the automated processing of security advisories to ensure faster reaction times and precise response to new threats and vulnerabilities. In this way IT management can concentrate on solutions rather than on filtering messages.
منابع مشابه
Semantic Insecurity: Security and the Semantic Web
Strangely enough, the Semantic Web has fallen behind the rest of the Web in terms of security. In particular, we note how TLS is not in use currently for the majority of URIs on the Semantic Web, and how existing Semantic Web standards need to be updated to take into account security best practices. We point out security and privacy flaws in WebID+TLS, and propose alternatives and solutions.
متن کاملSecurity standards for the semantic web
This paper first describes the developments in standards for the semantic web and then describes standards for secure semantic web. In particular XML security, RDF security, and secure information integration and trust on the semantic web are discussed. Some details of our research on access control and dissemination of XML documents are also given. Next privacy issues for the semantic web are ...
متن کاملTowards an Ontology-Driven Approach for the Interoperability Problem in Security Compliance
In today’s IT-centric, regulated and competitive environment, businesses rely more heavily on IT technologies. Organizations are often challenged by customers, business partners and legal entities to demonstrate their compliance to different IT security and performance standards. The existence of heterogeneous standards and regulations raises the interoperability problem for organizations havin...
متن کاملComputationally secure multiple secret sharing: models, schemes, and formal security analysis
A multi-secret sharing scheme (MSS) allows a dealer to share multiple secrets among a set of participants. in such a way a multi-secret sharing scheme (MSS) allows a dealer to share multiple secrets among a set of participants, such that any authorized subset of participants can reconstruct the secrets. Up to now, existing MSSs either require too long shares for participants to be perfect secur...
متن کاملSemantic enterprise application integration standards
This paper investigates the potential of the Semantic Web technologies to support a semantic-based Enterprise Application Integration (EAI) standards architecture. We give detailed information of the support that these technologies and the underlying Description Logics (DL) formalism provide for the integration task. Our main aim is to assess the potential impact of these emerging technologies ...
متن کامل