Home
Scholarly Works
Building a comprehensive and multi-dimensional...
Journal article

Building a comprehensive and multi-dimensional information security ontology: elicitation process and OWL implementation

Abstract

Ontology is an important tool that provides a full representation of domain knowledge. To build ontology from heterogeneous data sources, a comprehensive process is required to extract concepts with their relationships and then conveniently visualize them. In this paper, an ontology construction process is proposed to automatically build a Multi-Dimensional Information Security Ontology, named MDISOnt. The proposed process includes three main stages. The first is the ontology design that gives the hierarchical representation of security concepts. The second starts from ISO/IEC 27000 standard document and enriches the ontology obtained in stage 1 with semantic and synonym relationships. The third consists of the implementation of the obtained ontology by highlighting the security dimensional views and ontology modules. The obtained ontology, which we named MDISOnt helps security specialists and decision-makers remove the ambiguous understanding of the information security domain, decompose security into several perspectives using dimensional views and modules, and efficiently manage information security management in an organization. Compared to the prominent OWL InfoSec ontologies available in the literature, the comparative study demonstrates the outperformance of MDISOnt in terms of accuracy, understandability, and cohesion.

Authors

Meriah I; Ben Arfa Rabai L; Khedri R

Journal

Knowledge and Information Systems, Vol. 67, No. 1, pp. 167–195

Publisher

Springer Nature

Publication Date

January 1, 2025

DOI

10.1007/s10115-024-02308-y

ISSN

0219-1377

Contact the Experts team