Ajou University repository

Understanding and recommending security requirements from problem domain ontology: A cognitive three-layered approach
Citations

SCOPUS

21

Citation Export

DC Field Value Language
dc.contributor.authorKim, Bong Jae-
dc.contributor.authorLee, Seok Won-
dc.date.issued2020-11-01-
dc.identifier.issn0164-1212-
dc.identifier.urihttps://dspace.ajou.ac.kr/dev/handle/2018.oak/31366-
dc.description.abstractSocio-technical systems (STS) are inherently complex due to the heterogeneity of its intertwined components. Therefore, ensuring STS security continues to pose significant challenges. Persistent security issues in STS are extremely critical to address as threats to security can affect entire enterprises, resulting in significant recovery costs. A profound understanding of the problems across multiple dimensions of STS is the key in addressing such security issues. However, we lack a systematic acquisition of the scattered knowledge related to design, development, and execution of STS. In this work, we methodologically analyze security issues from a requirements engineering perspective. We propose a cognitive three-layered framework integrating various modeling methodologies and knowledge sources related to security. This framework helps in understanding essential components of security and making recommendations of security requirements regarding threat analyses and risk assessments using Problem Domain Ontology (PDO) knowledge base. We also provide tool support for our framework. With the goal-oriented security reference model, we demonstrate how security requirements are recommended based on PDO, with the help of the tool. The organized acquisition of knowledge from SME groups and the domain working group provides rich context of security requirements, and also enhances the re-usability of the knowledge set.-
dc.description.sponsorshipThis research was supported by the Basic Science Research Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Science and ICT (NRF-2020R1F1A1075605 ). The authors would like to thank anonymous reviewers for their valuable comments. We are also immensely grateful to Sangeeta Dey and Sihn Hye Park for their help on the manuscript.-
dc.description.sponsorshipThis research was supported by the Basic Science Research Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Science and ICT (NRF-2020R1F1A1075605). The authors would like to thank anonymous reviewers for their valuable comments. We are also immensely grateful to Sangeeta Dey and Sihn Hye Park for their help on the manuscript.-
dc.language.isoeng-
dc.publisherElsevier Inc.-
dc.subject.meshKnowledge sources-
dc.subject.meshLayered approaches-
dc.subject.meshModeling methodology-
dc.subject.meshMultiple dimensions-
dc.subject.meshReference modeling-
dc.subject.meshSecurity issues-
dc.subject.meshSecurity requirements-
dc.subject.meshSociotechnical systems-
dc.titleUnderstanding and recommending security requirements from problem domain ontology: A cognitive three-layered approach-
dc.typeArticle-
dc.citation.titleJournal of Systems and Software-
dc.citation.volume169-
dc.identifier.bibliographicCitationJournal of Systems and Software, Vol.169-
dc.identifier.doi10.1016/j.jss.2020.110695-
dc.identifier.scopusid2-s2.0-85086587944-
dc.identifier.urlhttps://www.journals.elsevier.com/journal-of-systems-and-software-
dc.subject.keywordOntology-
dc.subject.keywordRequirements engineering-
dc.subject.keywordSecurity-
dc.description.isoafalse-
dc.subject.subareaSoftware-
dc.subject.subareaInformation Systems-
dc.subject.subareaHardware and Architecture-
Show simple item record

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Lee, Seok-Won Image
Lee, Seok-Won이석원
Department of Software and Computer Engineering
Read More

Total Views & Downloads

File Download

  • There are no files associated with this item.