<?xml version="1.0" encoding="UTF-8"?>
<TEI xml:space="preserve" xmlns="http://www.tei-c.org/ns/1.0" 
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
xsi:schemaLocation="http://www.tei-c.org/ns/1.0 https://raw.githubusercontent.com/kermitt2/grobid/master/grobid-home/schemas/xsd/Grobid.xsd"
 xmlns:xlink="http://www.w3.org/1999/xlink">
	<teiHeader xml:lang="en">
		<fileDesc>
			<titleStmt>
				<title level="a" type="main">Towards a Human Factors Ontology for Cyber Security</title>
			</titleStmt>
			<publicationStmt>
				<publisher/>
				<availability status="unknown"><licence/></availability>
			</publicationStmt>
			<sourceDesc>
				<biblStruct>
					<analytic>
						<author>
							<persName><forename type="first">Alessandro</forename><surname>Oltramari</surname></persName>
							<affiliation key="aff0">
								<orgName type="institution">Carnegie Mellon University Pittsburgh</orgName>
								<address>
									<country key="US">USA</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Diane</forename><surname>Henshel</surname></persName>
							<affiliation key="aff1">
								<orgName type="institution">Indiana University Bloomington</orgName>
								<address>
									<country key="US">USA</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Mariana</forename><surname>Cains</surname></persName>
							<affiliation key="aff1">
								<orgName type="institution">Indiana University Bloomington</orgName>
								<address>
									<country key="US">USA</country>
								</address>
							</affiliation>
						</author>
						<author>
							<persName><forename type="first">Blaine</forename><surname>Hoffman</surname></persName>
							<affiliation key="aff2">
								<orgName type="laboratory">Army Research Laboratory</orgName>
								<address>
									<settlement>Aberdeen</settlement>
									<country key="US">USA</country>
								</address>
							</affiliation>
						</author>
						<title level="a" type="main">Towards a Human Factors Ontology for Cyber Security</title>
					</analytic>
					<monogr>
						<imprint>
							<date/>
						</imprint>
					</monogr>
					<idno type="MD5">E531FFB7F43B21CAD8636CC4A8D7B043</idno>
				</biblStruct>
			</sourceDesc>
		</fileDesc>
		<encodingDesc>
			<appInfo>
				<application version="0.7.2" ident="GROBID" when="2023-03-24T21:46+0000">
					<desc>GROBID - A machine learning software for extracting information from scholarly documents</desc>
					<ref target="https://github.com/kermitt2/grobid"/>
				</application>
			</appInfo>
		</encodingDesc>
		<profileDesc>
			<textClass>
				<keywords>
					<term>cyber security</term>
					<term>risk assessment</term>
					<term>human factors</term>
					<term>cyber operations</term>
				</keywords>
			</textClass>
			<abstract>
<div xmlns="http://www.tei-c.org/ns/1.0"><p>Traditional cybersecurity risk assessment is reactive and based on business risk assessment approach. The 2014 NIST Cybersecurity Framework provides businesses with an organizational tool to catalog cybersecurity efforts and areas that need additional support. As part of an on-going effort to develop a holistic, predictive cyber security risk assessment model, the characterization of human factors, which includes human behavior, is needed to understand how the actions of users, defenders (IT personnel), and attackers affect cybersecurity risk. Trust has been found to be a crucial element affecting an individual's role within a cyber system. The use of trust as a human factor in holistic cybersecurity risk assessment relies on an understanding how differing mental models, risk postures, and social biases impact the level trust given to an individual and the biases affecting the ability to give said trust. The Human Factors Ontology illustrates the individual characteristics, situational characteristics, and relationships that influence the trust given to an individual. Furthering the incorporation of ontologies into the science of cybersecurity will help decision-makers build the foundation needed for predictive and quantitative risk assessments.</p></div>
			</abstract>
		</profileDesc>
	</teiHeader>
	<text xml:lang="en">
		<body>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>I. INTRODUCTION</head></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>A. The Holistic Cybersecurity Risk Framework</head><p>The science of cybersecurity risk assessment has been reactive, narrow in focus, and based on a business risk assessment approach. More recently, the National Institute of Science and Technology (NIST) responded to the 2013 "Improving Critical Infrastructure Cybersecurity" Executive Order with the development of the 2014 NIST Cybersecurity Framework <ref type="bibr" target="#b0">[1,</ref><ref type="bibr" target="#b1">2]</ref>. The NIST framework aims to provide organizations and businesses with best risk management practices that can be implemented to improve the security and resilience of critical infrastructure. NIST recognizes that risk management is an iterative process of risk identification, risk assessment, and risk mitigation. While the NIST framework provides businesses and organizations with a neatly organized account of their cybersecurity efforts, the framework fails to capture the concept that humans are an inherent risk to any system in which they directly or indirectly participate.</p><p>To go beyond the current risk framework promulgated by NIST <ref type="bibr" target="#b0">[1,</ref><ref type="bibr" target="#b1">2]</ref>, risk assessment needs to be more holistic. In order to enable cybersecurity risk assessment to become more predictive, the process and models need to incorporate humans and risk factors together in a single model and use metrics that go beyond the direct assessment of classical vulnerabilities (confidentiality, integrity, accessibility, or CIA).</p><p>First, when considering CIA, the actual measurement or evaluation of these vulnerabilities will depend on the situation being modeled. Situations requiring cybersecurity risk assessment can include baseline assessments of network protection, but must also include situations in which the network is being used actively. The actual metrics for, say, protection of an SQL database containing personal information (social security numbers, for example) may be very different than the metrics needed to be assessed when evaluating risk related to a field operation using radios, walkie talkies or cell phones to convey information.</p><p>Second, other variables beyond CIA may be the relevant risk variables that need to be analyzed in a risk model. Take, for example, a situation in which information being used, generated in, or relayed by one network needs to be received in a specific time window either for another operation to begin or so that the information can be used maybe by the human who will receive the information. Within a military or other time critical context, the evaluation goes beyond time to access information; it must include time to act on the accessed information and can include time for completion of actions within a critical time window. In this example, time to completion of a task is the critical metric that must be tracked, and so must be incorporated into the risk model.</p><p>Third, humans are a part of virtually all networks, whether as users, defenders (and IT personnel) or attackers. All humans can introduce risk into the network, not just attackers, a consideration acknowledged when users are asked how they use the system (and system components) as part of the NIST risk management and risk assessment process. Defenders or IT personnel can also increase cyber risk if they are, for example, less skilled, or tired, or inside threats. Humans can also reduce risk in a cybersecurity system. Defenders put in place baseline protections, and then track attacks on the system to assess whether the protections have been breached and what needs to be done to increase system hardening (protections), counteract malware that may have introduced access to the system (or otherwise compromised the system and system assets), and repair damage to the system. Users can decrease risk by being aware of (and not being hooked by) spam or phishing efforts, ensuring their personal system assets are appropriately protected, and by not downloading infected files or accessing malware-linked websites. Therefore, human-dependent metrics must be included in a holistic risk analysis of cyber security.</p><p>A fully predictive cyber security risk assessment model will take into account humans as risk factors, and as risk mitigators, and will enable the incorporation of metrics that go beyond the classic CIA vulnerabilities. In order to develop such a model, we have been characterizing the universe of cybersecurity by framing the characteristics, attributes and, ultimately, metrics that can be use to describe the risks associated with any cyber network. The framework has multiple pieces, and metrics that are assessed at different levels.</p><p>Three main parts to the Cybersecurity Risk Framework identifies system level metrics, policy related metrics, and asset related metrics. System level metrics are evaluated at the full system level, such as probability of completion of a mission or a system level task. Policy level metrics evaluate the risks associated with the policies that govern the network and network assets. Asset level metrics are evaluated at the asset level, such as metrics to assess risks associated with specific machines, a virtual network, or an operating system. One piece of the asset level framework characterizes the Human Factors that introduce or mitigate risk in a cyber network <ref type="bibr" target="#b2">[3]</ref>, which is then being incorporated into an ontology. One goal of this framework and ontology is to identify the factors that contribute to a key aspect of human-related cyber risk, trust.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>B. An ontological approach to risk modeling</head><p>A recent report on quantification of cyber threats highlights the intrinsic complexity of the cyber domain [4]: in this document experts pinpoint the bottleneck of cyber threat assessment on the lack of "standardization and benchmarking of input variables", as conversely accomplished -they add -"by the car insurance industry" (p. <ref type="bibr" target="#b15">16</ref>). But if agreeing on the meaning of notions like 'age' and 'gender' of drivers, 'weight' and 'year of built' of cars, 'claims history', etc. seems mostly straightforward, specifying the semantics of concepts like 'system vulnerability', 'software usability', 'trust', 'password strength', etc. requires advanced technical knowledge, finegrained modeling primitives, and non-trivial metrics.</p><p>Little effort has been put into this standardization process. For instance, Fenz and Ekelhart propose an ontology based on four parts, i.e. security and dependability taxonomy, the underlying risk analysis methodology, the concepts of the IT infrastructure domain and a simulation enabling enterprises to analyze various policy scenarios <ref type="bibr" target="#b3">[5]</ref>. Notwithstanding the comprehensive investigation, the work presented in <ref type="bibr" target="#b3">[5]</ref> is affected by an underspecified notion of risk, conceived as "the probability that a successful attack occurs", which clearly fails to account for the mutual dependence between profiles of attackers, system vulnerabilities, level of expertise of the defenders, monetization of information loss resulting from data breaches, etc. In general, a too-coarse representation of risk is a pervasive problem in the state of the art on ontologies of cyber security: it's the case of <ref type="bibr" target="#b4">[6]</ref> and <ref type="bibr" target="#b5">[7]</ref> where the in-depth conceptual distinctions adopted to model cyber attacks are not matched by a corresponding level of detail in defining cyber threats and risk assessment procedures.</p><p>The most popular modeling solution in risk-related ontology research seems to be the reification of riskassessment and threat-quantification into the process of 'rating', whose attributes are expressed either qualitatively (e.g., by means of high, medium and low dimensions in the Likert scale) or quantitatively (measuring the probability of a risk). Note that in ontology modeling, reification of properties is commonly adopted as a method to bypass language expressivity limits: in RDF, for instance, a relation with arity n &gt; 2 can be represented with a statement about those n entities. Thus, for instance, we could represent the fact that a set of n cyber vulnerabilities exposes a system to a certain risk factor, by asserting a risk-rating statement about those known n vulnerabilities <ref type="bibr" target="#b7">[8]</ref>. An alternative approach comes from Enterprise Risk Management (ERM), an area that concerns the identification, assessment and mitigation of operational risk: for instance, Lykourentzou and colleagues focus on seven subclasses of events, i.e. 'Failure', 'Infrastructure disruption', 'Occupational incident', 'Fraud', 'Disaster', 'Attack', binding each of these event types to a wide spectrum of 'Root causes' and 'Treatment plans' to address risk factors <ref type="bibr" target="#b8">[9]</ref>. ERM's approaches can be effective not only to identify risk-related event patterns, but also to elicit the behavioral patterns in the adoption of risk management practices. In this context, ontologies supply an axiomatic infrastructure to mental models of risk-related patterns.</p><p>The rest of the paper is organized as follows: Section II makes the case for a holistic approach to risk in cyber security, introducing the role of trust ontologies; Section III focuses on the Human Factors Ontology (HUFO); finally, Section IV draws preliminary conclusions and sets an agenda for future research.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>II. RELATED WORK</head></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>A. Ontologies of cyber security</head><p>The U.S faces cyber attacks by rogue states and terrorist organizations on a daily basis. While greatly increased use of information systems has contributed enormously to economic growth, it has also made the U.S. vulnerable to a variety of cyber threats that are difficult to contrast and prevent. There are numerous factors that make cyber defense, and cyber security in general, especially problematic. The kinds of threats are diverse and span a wide spectrum of private and public interests: destruction or theft of data, interference with computer networks and information systems, disruption of the power grid and telecommunications, denial of services, etc. The legal and ethical status of cyber attacks or counterattacks by states are also unclear, at least when deaths or permanent destruction of physical objects does not result. It is still an open question what U.S. policy is or should be, and how cyber threats are analogous to traditional threats and policies-for example whether "first use" deterrence, and in-kind responses apply, and whether a policy of pure cyber defense does not put the far greater burden on attacked rather than attacking nations <ref type="bibr" target="#b9">[10]</ref>.</p><p>As these arguments suggest, untangling the complexity of cyber security does not solely depend on pinning down the computational elements into play, but demands a thorough analysis of the human factors involved. In this regard, cyber security must be studied in the context of "sociotechnical systems" <ref type="bibr" target="#b10">[11]</ref>, where the interaction between people and technology in workplace is central. Ontology analysis has recently proved to be an effective tool for investigating the defining aspects of that interaction <ref type="bibr" target="#b11">[12]</ref>.</p><p>Informed decisions emerge when a cyber analyst projects her observations into a broad context that factors in threat and attack types, space of defensive maneuvers, system vulnerabilities, risk assessment and mitigation under time constraints. Obrst and colleagues <ref type="bibr" target="#b12">[13]</ref> provide the most systematic description of a wide-ranging ontology of cyber security, but only a small portion of this large-scale project is devoted to the human component. Various agencies and corporations (NIST <ref type="bibr" target="#b0">[1,</ref><ref type="bibr" target="#b1">2]</ref>, MITRE <ref type="bibr" target="#b13">[14]</ref>, and Verizon <ref type="bibr" target="#b14">[15]</ref>) have formulated enumerations of types of malware, vulnerabilities, and exploitations: MITRE, which has been very active in this field, maintains two dictionaries, namely CVE (Common Vulnerabilities and Exposure<ref type="foot" target="#foot_0">1</ref> ) and CWE (Common Weakness Enumeration<ref type="foot" target="#foot_1">2</ref> ) and a classification of attack patterns (CAPEC -Common Attack Pattern Enumeration and Classification<ref type="foot" target="#foot_2">3</ref> ). Regardless of the important issues covered by these initiatives, they have two major problems: 1) machine-readability is not supported, making them ineffectual as computational models of cyber security; 2) the human component is mostly overlooked, making the resulting models partial in scope.</p><p>In order to overcome these problems, in the context of the Cyber Collaborative Research Alliance we are developing CRATELO, a three-level modular ontology of cyber security. In the next section we are going to describe the general features of CRATELO, focusing on the Human Factors Trust Ontology module (HUFO).</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>B. Trust ontologies</head><p>Ontology-based models of trust have been studied in various domains <ref type="bibr" target="#b15">[16]</ref>. In <ref type="bibr" target="#b16">[17]</ref>, the authors propose an intelligent and dynamic Service Level Agreement (SLA) based on a probabilistic ontology that detects warnings in a cloud computing environment. A generic service-oriented framework of trust ontologies is described in <ref type="bibr" target="#b17">[18]</ref>. A trust ontology aiming at improving the semantic specification of trust networks in the context of social institutions and ecosystems is discussed in <ref type="bibr" target="#b18">[19]</ref>. In <ref type="bibr" target="#b19">[20]</ref>, the author focuses on six general areas to derive trust for a system, namely user, hardware, software, network, machines, and the applications, mapping trust associated with each area to specific attributes. An ontology-based approach to integrate semantic web based trust networks with provenance information to evaluate and filter a set of assertions is presented in <ref type="bibr" target="#b20">[21]</ref>. In <ref type="bibr" target="#b21">[22]</ref>, a reference ontology to develop privacy preserving negotiation systems is delineated.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>III. THE HUMAN FACTORS TRUST ONTOLOGY</head></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>A. The Human Factors Trust Ontology</head><p>Adopting a standard understanding and definition of terms and concepts is a foundational requirement for good cyber security practice, owing to the nature of the space and the need for rapid, efficient decision-making. Cyber security is an adversarial space, where defenders must project possibilities and be ahead of their opposition in order to be successful. Enacting strategies favors selecting a suitable course of action in minimal time over exhaustively searching <ref type="bibr" target="#b22">[23,</ref><ref type="bibr" target="#b23">24]</ref>. Furthermore, the data available is not always straightforward, requiring collection and parsing in order to construct an understanding of the situation(s) at hand. Numerous sources of relevant information are often applicable, including network monitoring tools, logs, system statuses, and hardware monitors. Analysts are situated at the center of a large-scale data fusion process, identifying and defining information through patterns and relationships to perceive the ground truth of the cyber systems and assets they are defending and monitoring <ref type="bibr" target="#b24">[25,</ref><ref type="bibr" target="#b25">26,</ref><ref type="bibr" target="#b26">27]</ref>. Once collected, the information must be appropriately combined, categorized, and communicated in order to provide a useful and accurate picture of the world on which future strategies can be based. Simply stated, cyber defense is heavily focused on the human analysts and agents involved in a data fusion and situation awareness process.</p><p>Through processing of data, defenders can draw conclusions and decide how to respond to evolving scenarios. Implicit within the workload is a desire and preference for information that can be trusted, a concept that requires a lot of unpacking to properly understand. In fact, conceptualizing trust in order to evaluate its role and presence within a system is itself a difficult problem; there are literally hundreds of definitions of trust covering interpersonal trust, trust in automation (system trust), and human-machine interaction <ref type="bibr" target="#b27">[28]</ref>. However, that variety only strengthens the argument for constructing and supporting an ontological representation of cyber security. The core similarities of cyber security and the tasks involved are essentially the same <ref type="bibr" target="#b28">[29]</ref>, which also supports the creation of a standard ontology. Thus we should be able to describe the human factors that influence trust in a way that can be applicable regardless of the specific cyber environment or organization involved and that will help explicate the role of trust in risk assessment and evaluation.</p><p>Assessing cyber security risks is a multi-component, multi-tiered problem that involves hardware, software, environmental, and human factors. Effective and successful efforts must consider impacts beyond the computer assets and network, taking a more holistic approach that considers the users, defenders, and attackers involved <ref type="bibr" target="#b2">[3]</ref>. Exploring the differences among human roles and human factors includes exploring how trust permeates risk assessment, such as trust in information, in people, or in security policies. Information is not uniformly trusted and incorporated into situation awareness and defender responses automatically, but it is built over time as those involved develop relationships, progress through training, and gain experience <ref type="bibr" target="#b29">[30]</ref>. Individuals grow trust in one another through working together, and people gain trust in systems as they continue to demonstrate consistent behavior. Previous definitions of trust aggregate characteristics into a whole sum, including concepts such as competence, benevolence, integrity, predictability, attitude, intention, behavior, reliability, dependability, and faith <ref type="bibr" target="#b30">[31]</ref> [32] <ref type="bibr" target="#b19">[20]</ref>. The human factors trust ontology aims to map these concepts into understood and explicit relationships that tie together risk assessment across the human and humansystem interactions within the cyber security space.</p><p>As part of an ongoing development of holistic cyber security risk assessment, we have been creating a framework that enables predictive and proactive defenses <ref type="bibr" target="#b32">[33,</ref><ref type="bibr" target="#b33">34,</ref><ref type="bibr" target="#b34">35]</ref>. A critical component of this process has been the characterization of human factors, such as trust, and mapping the relevant risk attributes to the risk spaces involved in cyber security. Overall, this is a process of creating, enumerating, and solidifying risk characteristics and factors, and in many cases refining them and relating them to the human factors. The latter are broken into three main categories of attacker, defender, and user with a shared core of spaces (their behavioral characteristics, knowledge and skill characteristics, situational characteristics, and traits that influence behavior) that create the definition of each <ref type="bibr" target="#b2">[3]</ref>. The framework (see Figure <ref type="figure" target="#fig_0">1</ref>) can be navigated from top to bottom, the lower tiers breaking out into the more specific metrics and concepts that, collectively, describe and detail these core spaces, which allows for the mapping of attributes to measures and data that can be used to create risk evaluations.</p><p>Situational Characteristics focus on where in the system/network the individual is positioned and the level of insider access they possess, denoting when this access is authorized or unauthorized. A person's situational characteristics also influence the knowledge they can access and may influence the attention they bring to a situation. For example, a user who is an executive of a company may have significant authorized access to assets but lack the same level of attentiveness to security concerns and information that a network analyst possesses. Knowledge and skill characteristics call to attention the experience, expertise, and situational awareness capabilities of the individual, including demographics such as years working in a position and training as well as their proficiency with relevant tools and techniques. Behavioral Characteristics are split into spaces such as motivation, rationality, malevolence vs. benevolence, and integrity. For example, a defender who is rational, benevolent, and has a record of following through with work and being accountable for his or her responsibilities will likely exhibit persistence in defending assets and building appropriate situational awareness. We have expanded the framework to include traits that influence the behavioral characteristics, including ideology, ethical attributes, risk averseness, and personality traits. Each of these may scale the behavioral characteristics in some fashion or serve as the driving force behind a person's integrity, benevolence, or rational approach to cyber security situations. Collectively, these characteristics and traits impact the individual's interactions with mission assets and play a role in determining risk. For example, defender with poor motivation and integrity, insufficient knowledge, and appropriate insider access can present a higher risk, whereas an attacker with high motivation and knowledge despite limited insider access also poses higher risk.</p><p>Trust also comes through across these spaces. The predictability and reliability of an individual generates a sense of trust in his or her actions and creates a reputation for that individual. The expertise and knowledge possessed can instill a faith or confidence in the work a defender will do, and users with sufficient integrity will be trusted to follow security policy and not act maliciously within the network. In effect, the human factors of trust directly associates with risk evaluation of cyber situations, and we can explore the relationships across the human factors of cyber security to discover where risk manifests and how trust is generated and influenced. Integrating the human factors framework into a cyber security ontology provides a logical means to explicate relationships both obvious and unintuitive, follow their connections, and evaluate trust's presence and impact on the risk present within a given network.  B. HUFO and Trust: an overview HUFO (see Figure <ref type="figure" target="#fig_1">2 above</ref>) is part of CRATELO <ref type="bibr" target="#b35">[36]</ref>, a suite of integrated ontologies of cyber security, designed on the basis of DOLCE top level <ref type="bibr" target="#b36">[37]</ref>, extended with a security-related middle ontology. These top, middle and domain level ontologies currently add up to 330 classes, connected by 162 relationships (132 object properties and 30 datatype properties) and encoded in OWL-DL. The logical expressivity of CRATELO is SRIQ, a decidable extension of the description logic SHIN (for more details see <ref type="bibr" target="#b37">[38]</ref>).</p><p>The relation holding between the human factors and the metrics used to assess them is captured by the semantic characterization of 'qualities' and 'quality spaces', which has been originally formulated by <ref type="bibr" target="#b38">[39]</ref> and subsequently formalized in DOLCE ontology <ref type="bibr" target="#b36">[37]</ref>. Intuitively, a quality corresponds to an individual attribute of a specific entity, as 'predictability' or 'reliability' can be considered attributes of 'trust'; a quality space is the abstract representation of an attribute's semantics, e.g. a boolean space that denotes the 'reliable/unreliable' dichotomy. An important topological property of quality spaces is that their dimensional structure can vary. For instance, the 'reliability space' can be more complex than a bidimensional configuration: in particular, this is the case when reliability is conceptualized as probabilistic distribution between maximum reliability (100%) and complete unrealibility (0%). The atomic parts of a quality space, which collectively denote the range of values used to specify an attribute's semantics, are called 'quality regions'. Note that quality regions of a linear space reduce to points.</p><p>As mentioned above, 'predictability' and 'reliability' are conceived in HUFO as components of 'trust', a complex factor that is influenced by inherent and external characteristics, in combination with measures of human performance in a given situation. Hence, trust is not only associated to human characteristics, but emerges as an essential aspect of sociotechnical systems: the hybrid nature of trust is particularly evident in the cyber security domain, where a trustworthy interaction with computer network systems is the 'conditio sine qua non' for a defender/attacker to accomplish a mission in cyberspace <ref type="foot" target="#foot_3">4</ref> .</p><p>Figure <ref type="figure" target="#fig_1">2</ref> represents an overview of HUFO generated using OWLGrEd<ref type="foot" target="#foot_4">5</ref> : the purple links represent subsumption relationship between classes, whereas the dotted arrows indicate either the 'component-of' or the 'influenced-by' property (textual labels in the figure disambiguate the equivalent graphical notations); classes are depicted as yellow boxes, instances as green boxes. The object property 'component of', holding between attributes and qualities, is modeled as a generic 'part-of' relation <ref type="bibr" target="#b39">[40]</ref>, whereas the 'influenced-by' relation reflects DOLCE's characterization of general dependence, to highlight the strong connection between the assessment (existence) of proper internal and external characteristics and the computation of the derived trust level. Note that objective, subjective, and objectivesubjective designate the sorts of metrics that can be predicated to each human factor (represented in Figure <ref type="figure" target="#fig_0">1</ref>). An objective metric represents characteristics that are based in quantifiable and unbiased facts such as highest level of education completed. A subjective metric represents characteristics based in human decision-making and assumptions such as political rationality. An objectivesubjective metric represents characteristics that are based in fact while also influenced by human decision-making such as emotional state. These metrics types are modeled as instances in HUFO: the use of meta-classes would have required OWL-Full, which is the undecidable fragment of OWL, and therefore unfit for reasoning. Consequently, we opted for modeling the three types of metrics as a collection of individual instances (range) associated to human factors classes (domain) through the object property 'has metric'.</p></div>
<div xmlns="http://www.tei-c.org/ns/1.0"><head>IV. CONCLUSIONS AND FUTURE WORK</head><p>In this paper we examined the effort of building a human factors ontology (HUFO) as part of a broader ontology of cyber security (CRATELO). In particular, we focused on the notion of trust, showing its ties with the inherent and external characteristics of humans interacting with computer networks. In the long term, we envision to apply HUFO in support of risk assessment and risk prioritazion in cyber operations.</p><p>The semantic model outlined in this paper is only a first, preliminary step in the process of porting a larger model of the cyber security ecosystem into a computational ontology. The holistic nature of our approach makes the task exceptionally challenging and, to the best of our knowledge, uniquely systematic in cyber security research. Despite the complex problems we are trying to solve, we're also convinced that, in the forward-looking vision of the ARL Cyber Security Collaborative Research Alliance, our approach sets a realistic and crucial milestone toward the foundation of a science of cyber security.</p></div><figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_0"><head>Figure 1 -</head><label>1</label><figDesc>Figure 1 -Trust Framework of Human Factors in Cyber Security.</figDesc><graphic coords="5,46.65,56.00,518.36,207.85" type="bitmap" /></figure>
<figure xmlns="http://www.tei-c.org/ns/1.0" xml:id="fig_1"><head>Figure 2 -</head><label>2</label><figDesc>Figure 2 -A visualization of HUFO.</figDesc><graphic coords="5,46.65,311.35,518.35,197.35" type="bitmap" /></figure>
			<note xmlns="http://www.tei-c.org/ns/1.0" place="foot" n="1" xml:id="foot_0">https://cve.mitre.org/</note>
			<note xmlns="http://www.tei-c.org/ns/1.0" place="foot" n="2" xml:id="foot_1">https://cwe.mitre.org/ 2 https://cwe.mitre.org/</note>
			<note xmlns="http://www.tei-c.org/ns/1.0" place="foot" n="3" xml:id="foot_2">https://capec.mitre.org/</note>
			<note xmlns="http://www.tei-c.org/ns/1.0" place="foot" n="4" xml:id="foot_3">This is the case, for instance, when a cyber analyst uses a network-based intrusion prevention system (or NIPS) to monitor and protect a given network environment from cyber attacks.</note>
			<note xmlns="http://www.tei-c.org/ns/1.0" place="foot" n="5" xml:id="foot_4">http://owlgred.lumii.lv/</note>
		</body>
		<back>

			<div type="acknowledgement">
<div xmlns="http://www.tei-c.org/ns/1.0"><head>ACKNOWLEDGMENTS</head><p>This research was sponsored by the Army Research Laboratory and was accomplished under Cooperative Agreement Number W911NF-13-2-0045 (ARL Cyber Security CRA). The views and conclusions contained in this document are those of the authors and should not be interpreted as representing the official policies, either expressed or implied, of the Army Research Laboratory or the U.S. Government. The U.S. Government is authorized to reproduce and distribute reprints for Government purposes notwithstanding any copyright notation here on. BIBLIOGRAPHY</p></div>
			</div>

			<div type="references">

				<listBibl>

<biblStruct xml:id="b0">
	<monogr>
		<title level="m" type="main">Framework for Improving Critical Infrastructure Cybersecurity</title>
		<imprint>
			<date type="published" when="2014">1 2014</date>
		</imprint>
		<respStmt>
			<orgName>Technology, National Institute of Standards and ; Dept. of Commerce, NIST</orgName>
		</respStmt>
	</monogr>
</biblStruct>

<biblStruct xml:id="b1">
	<analytic>
		<title level="a" type="main">Guide for Conducting Risk Assessments</title>
	</analytic>
	<monogr>
		<title level="j">Special Publication</title>
		<imprint>
			<biblScope unit="page" from="800" to="830" />
		</imprint>
		<respStmt>
			<orgName>Technology, National Institute of Standards and ; US Dept. of Commerce, NIST</orgName>
		</respStmt>
	</monogr>
</biblStruct>

<biblStruct xml:id="b2">
	<analytic>
		<title level="a" type="main">Trust as a Human Factor in Holistic Cyber Security Risk Assessment</title>
		<author>
			<persName><forename type="first">M</forename><surname>Hoffman</surname></persName>
		</author>
		<author>
			<persName><forename type="first">B</forename><surname>Kelley</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Henshel</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Cains</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">6th International Conference on Applied Human Factors and Ergonomics (AHFE)</title>
				<imprint>
			<date type="published" when="2015">2015</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b3">
	<analytic>
		<title level="a" type="main">Formalizing Information Security Knowledg</title>
		<author>
			<persName><forename type="first">S</forename><surname>Ekelhart</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Fenz</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">the International Symposium on Information, Computer, and Communications Security (ASIACCS &apos;09)</title>
				<meeting><address><addrLine>New York</addrLine></address></meeting>
		<imprint>
			<biblScope unit="page" from="183" to="194" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b4">
	<analytic>
		<title level="a" type="main">CYC: Using Common Sense Knowledge to Overcome Brittleness and Knowledge Acquisition Bottlenecks</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">B</forename><surname>Prakash</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Shepherd</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Lenat</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Artificial Intelligence</title>
		<imprint>
			<biblScope unit="volume">6</biblScope>
			<biblScope unit="issue">4</biblScope>
			<biblScope unit="page" from="65" to="85" />
			<date type="published" when="1985">1985</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b5">
	<analytic>
		<title level="a" type="main">Ontology Development for Industrial Risk Analysis</title>
		<author>
			<persName><forename type="first">A</forename><surname>Lenne</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Debray</surname></persName>
		</author>
		<author>
			<persName><forename type="first">B</forename><surname>Assali</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">IEEE STIDS 2015 Proceedings Page 31</title>
				<imprint/>
	</monogr>
</biblStruct>

<biblStruct xml:id="b6">
	<monogr>
		<title level="m">International Conference on Information &amp; Communication Technologies: from Theory to Applications</title>
				<meeting><address><addrLine>Damascus</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2008">2008</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b7">
	<monogr>
		<title level="m" type="main">Jena: Implementing the RDF Model and Syntax Specification</title>
		<author>
			<persName><forename type="first">B</forename><surname>Mcbride</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2001">2001</date>
			<pubPlace>SemWeb, Chicago</pubPlace>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b8">
	<analytic>
		<title level="a" type="main">Ontology-based Operational Risk Management</title>
		<author>
			<persName><forename type="first">I</forename><surname>Papadaki</surname></persName>
		</author>
		<author>
			<persName><forename type="first">K</forename><surname>Lykourentzou</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Djaghloul</surname></persName>
		</author>
		<author>
			<persName><forename type="first">Y</forename><surname>Latour</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Charalabis</surname></persName>
		</author>
		<author>
			<persName><forename type="first">I</forename><surname>Kapetanios</surname></persName>
		</author>
		<author>
			<persName><forename type="first">E</forename><surname>Kalliakmanis</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">13th Conference on Commerce and Enterprise Computing (CEC)</title>
				<imprint/>
	</monogr>
</biblStruct>

<biblStruct xml:id="b9">
	<analytic>
		<title level="a" type="main">The Essential Features of an Ontology for Cyber Warfare</title>
		<author>
			<persName><forename type="first">R</forename><surname>Dipert</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Conflict and Cooperation in Cyberspace: The Challenge to National Security</title>
				<editor>
			<persName><forename type="first">A</forename><surname>Lowther</surname></persName>
		</editor>
		<editor>
			<persName><forename type="first">P</forename><surname>Yannakogeorgos</surname></persName>
		</editor>
		<imprint>
			<publisher>Taylor &amp; Francis</publisher>
			<date type="published" when="2013">2013</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b10">
	<monogr>
		<author>
			<persName><forename type="first">K</forename><forename type="middle">B</forename><surname>De Greene</surname></persName>
		</author>
		<title level="m">Sociotechnical systems: factors in analysis, design, and management</title>
				<imprint>
			<publisher>Prentice-Hall</publisher>
			<date type="published" when="1973">1973</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b11">
	<analytic>
		<title level="a" type="main">Open Ontology-Driven Sociotechnical Systems: Transparency as a Key for Business Resiliency</title>
		<author>
			<persName><forename type="first">N</forename><surname>Guarino</surname></persName>
		</author>
		<author>
			<persName><forename type="first">E</forename><surname>Bottazzi</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Ferrario</surname></persName>
		</author>
		<author>
			<persName><forename type="first">G</forename><surname>Sartor</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Information Systems: Crossroads for Organization, Management, Accounting and Engineering</title>
				<imprint>
			<date type="published" when="2012">2012</date>
			<biblScope unit="page" from="535" to="542" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b12">
	<analytic>
		<title level="a" type="main">Developing an Ontology of the Cyber Security Domain</title>
		<author>
			<persName><forename type="first">L</forename><surname>Obrst</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Chase</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Markeloff</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">STIDS 2012</title>
				<meeting><address><addrLine>Fairfax, VA</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2012">2012</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b13">
	<monogr>
		<title level="m" type="main">Common Malware Enumeration list</title>
		<author>
			<persName><surname>Mitre</surname></persName>
		</author>
		<ptr target="http://cme.mitre.org/data/list.html" />
		<imprint/>
	</monogr>
</biblStruct>

<biblStruct xml:id="b14">
	<monogr>
		<author>
			<persName><surname>Verizon</surname></persName>
		</author>
		<title level="m">Data Breach Investigation Report</title>
				<imprint>
			<date type="published" when="2015">2015</date>
		</imprint>
	</monogr>
	<note>Online</note>
</biblStruct>

<biblStruct xml:id="b15">
	<analytic>
		<title level="a" type="main">Towards an Ontology of Trust</title>
		<author>
			<persName><forename type="first">L</forename><surname>Viljanen</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Trust, Privacy, and Security in Digital Business</title>
				<meeting><address><addrLine>Berlin-Heidelberg</addrLine></address></meeting>
		<imprint>
			<publisher>Springer-Verlag</publisher>
			<date type="published" when="2005">2005</date>
			<biblScope unit="volume">3592</biblScope>
			<biblScope unit="page" from="175" to="184" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b16">
	<analytic>
		<title level="a" type="main">Bayesian network, and probabilistic ontology driven trust model for sla management of cloud services</title>
		<author>
			<persName><forename type="first">O</forename></persName>
		</author>
		<author>
			<persName><forename type="first">Hafid</forename></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><forename type="middle">A</forename><surname>Serhani</surname></persName>
		</author>
		<author>
			<persName><forename type="first">Jules</forename></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">IEEE International Conference on Cloud Networking</title>
				<imprint>
			<date type="published" when="2014">2014</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b17">
	<analytic>
		<title level="a" type="main">Trust ontologies for e-service environments</title>
		<author>
			<persName><forename type="first">E</forename><surname>Dillon</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><forename type="middle">S</forename><surname>Hussain</surname></persName>
		</author>
		<author>
			<persName><forename type="first">F</forename><surname>Chang</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">International Journal of Intelligent Systems</title>
		<imprint>
			<biblScope unit="volume">22</biblScope>
			<biblScope unit="page" from="519" to="545" />
			<date type="published" when="2007">2007</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b18">
	<analytic>
		<title level="a" type="main">Structural determination of ontology-driven trust networks in semantic social institutions and ecosystems</title>
		<author>
			<persName><forename type="first">N</forename><surname>Matskin</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><surname>Dokoohaki</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">International Conference on Mobile Ubiquitous Computing</title>
				<meeting><address><addrLine>Papeete, France</addrLine></address></meeting>
		<imprint>
			<publisher>Systems, Services and Technologies</publisher>
			<date type="published" when="2007-11-09">4-9 Nov. 2007. 2007</date>
			<biblScope unit="page" from="263" to="268" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b19">
	<analytic>
		<title level="a" type="main">Trust metrics in information fusion</title>
		<author>
			<persName><forename type="first">E</forename><surname>Blasch</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">SPIE 9119 -Machine Intelligence and Bio-inspired Computation: Theory and Applications VIII</title>
				<imprint>
			<date type="published" when="2014">2014</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b20">
	<analytic>
		<title level="a" type="main">Trust network-based filtering of aggregated claims</title>
		<author>
			<persName><forename type="first">J</forename><surname>Parsia</surname></persName>
		</author>
		<author>
			<persName><forename type="first">B</forename><surname>Goldbeck</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">International Journal of Metadata, Semantics and Ontologies</title>
		<imprint>
			<biblScope unit="volume">1</biblScope>
			<biblScope unit="issue">1</biblScope>
			<biblScope unit="page" from="58" to="65" />
			<date type="published" when="2006">2006</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b21">
	<analytic>
		<title level="a" type="main">Achieving privacy in trust negotiations with an ontology based approach</title>
		<author>
			<persName><forename type="first">A</forename><forename type="middle">C</forename><surname>Bertino</surname></persName>
		</author>
		<author>
			<persName><forename type="first">E</forename><forename type="middle">Ferrari</forename><surname>Squicciarini</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">IEEE Transactions on Dependable and Secure Computing</title>
		<imprint>
			<biblScope unit="volume">3</biblScope>
			<biblScope unit="issue">1</biblScope>
			<biblScope unit="page" from="13" to="30" />
			<date type="published" when="2006-03">Jan-Mar 2006</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b22">
	<analytic>
		<title level="a" type="main">Recognition-primed-decision</title>
		<author>
			<persName><forename type="first">G</forename><forename type="middle">A</forename><surname>Klein</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Advances of Machine-System Reserch</title>
				<editor>
			<persName><forename type="first">W</forename><forename type="middle">B</forename><surname>Rouse</surname></persName>
		</editor>
		<meeting><address><addrLine>Greenwich, CT</addrLine></address></meeting>
		<imprint>
			<publisher>JAI Press</publisher>
			<date type="published" when="1989">1989</date>
			<biblScope unit="volume">5</biblScope>
			<biblScope unit="page" from="47" to="92" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b23">
	<analytic>
		<title level="a" type="main">Rapid decision making on the fire ground</title>
		<author>
			<persName><forename type="first">G</forename><forename type="middle">A</forename><surname>Calderwood</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Clinton-Cirocco</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Klein</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Human Factors Society 30th Annual Meeting</title>
				<imprint>
			<biblScope unit="page" from="576" to="580" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b24">
	<analytic>
		<title level="a" type="main">Introduction to Level 5 Fusion: the Role of the User</title>
		<author>
			<persName><forename type="first">E</forename><surname>Blasch</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Handbook of Multisensor Data Fusion</title>
				<editor>
			<persName><forename type="first">D</forename><surname>Hall</surname></persName>
		</editor>
		<editor>
			<persName><forename type="first">J</forename><forename type="middle">M E</forename><surname>Llinas</surname></persName>
		</editor>
		<editor>
			<persName><surname>Liggins</surname></persName>
		</editor>
		<imprint>
			<publisher>CRC Press</publisher>
			<date type="published" when="2008">2008</date>
			<biblScope unit="page" from="503" to="535" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b25">
	<monogr>
		<title level="m" type="main">Application of the JDL Data Fusion Process Model for Cyber Security</title>
		<author>
			<persName><forename type="first">N</forename><forename type="middle">A</forename><surname>Giacobe</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2010">2010</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b26">
	<analytic>
		<title level="a" type="main">User Information Fusion Decision Making Analysis with the C-OODA Model</title>
		<author>
			<persName><forename type="first">E</forename><forename type="middle">P</forename><surname>Breton</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Valin</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Blasch</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">14th International Conference on Information Fusion</title>
				<imprint>
			<date type="published" when="2011">2011</date>
			<biblScope unit="page" from="2082" to="2089" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b27">
	<analytic>
		<title level="a" type="main">What Is Trust? Defining the Construct Across Domains</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">R</forename><surname>Billings</surname></persName>
		</author>
		<author>
			<persName><forename type="first">K</forename><forename type="middle">E</forename><surname>Schaefer</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><surname>Llorens</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><forename type="middle">A</forename><surname>Hancock</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">American Psychological Association Conference (Division 21)</title>
				<meeting><address><addrLine>Orlando, FL</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2012">2012</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b28">
	<analytic>
		<title level="a" type="main">The real work of computer network defense analysts</title>
		<author>
			<persName><forename type="first">A</forename><surname>Whitley</surname></persName>
		</author>
		<author>
			<persName><forename type="first">K</forename><surname>D'amico</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Workshop on Visualization for Computer Security</title>
				<imprint>
			<date type="published" when="2008">2008</date>
			<biblScope unit="page" from="19" to="37" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b29">
	<analytic>
		<title level="a" type="main">URREF self-confidence in information fusion trust</title>
		<author>
			<persName><forename type="first">A</forename><surname>Jøsang</surname></persName>
		</author>
		<author>
			<persName><forename type="first">J</forename><surname>Dezert</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><forename type="middle">C G</forename><surname>Costa</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A.-L</forename><forename type="middle">E</forename><surname>Jousselme</surname></persName>
		</author>
		<author>
			<persName><surname>Blasch</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">17th International Conference on Information Fusion (FUSION&apos;2014)</title>
				<meeting><address><addrLine>Salamanca, Spain</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2014">2014</date>
			<biblScope unit="page" from="1" to="8" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b30">
	<analytic>
		<title level="a" type="main">Trust in Cybersocieties: Integrating the Human and Artificial Perspectives</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">H</forename><surname>Chervany</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><forename type="middle">L</forename><surname>Mcknight</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="s">Lecture Notes in Computer Science</title>
		<editor>, M. Singh, Y.-H. Tan R. Falcone</editor>
		<imprint>
			<biblScope unit="page" from="27" to="54" />
			<date type="published" when="2001">2001</date>
			<publisher>Springer</publisher>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b31">
	<analytic>
		<title level="a" type="main">Trust in automation: Part II. Experimental studies of trust and human Intervention in a process control simulation</title>
		<author>
			<persName><forename type="first">B</forename><surname>Moray</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><surname>Muir</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="j">Ergonomics</title>
		<imprint>
			<biblScope unit="volume">39</biblScope>
			<biblScope unit="issue">3</biblScope>
			<biblScope unit="page" from="429" to="460" />
			<date type="published" when="1996">1996</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b32">
	<analytic>
		<title level="a" type="main">Human Actors&apos; Roles in Holistic Cyber Security Risk Assessment</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">S</forename><surname>Henshel</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Alexeev</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Rajivan</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><forename type="middle">G</forename><surname>Cains</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">World Congress on Risk</title>
				<meeting><address><addrLine>Singapore</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2015">2015</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b33">
	<analytic>
		<title level="a" type="main">Risk Parameters in Holistic Cyber Security Risk Assessment</title>
		<author>
			<persName><forename type="first">A</forename><surname>Alexeev</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><forename type="middle">G</forename><surname>Cains</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><forename type="middle">D S</forename><surname>Rajivan</surname></persName>
		</author>
		<author>
			<persName><surname>Henshel</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">World Congress on Risk</title>
				<meeting><address><addrLine>Singapore</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2015">2015</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b34">
	<analytic>
		<title level="a" type="main">Holistic Cyber Security Risk Assessment</title>
		<author>
			<persName><forename type="first">D</forename><forename type="middle">S</forename><surname>Henshel</surname></persName>
		</author>
		<author>
			<persName><forename type="first">M</forename><forename type="middle">G</forename><surname>Cains</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Society for Risk Analysis</title>
				<meeting><address><addrLine>Denver, Denver (CO)</addrLine></address></meeting>
		<imprint>
			<date type="published" when="2014">2014</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b35">
	<analytic>
		<title level="a" type="main">Building an Ontology of Cyber Security</title>
		<author>
			<persName><forename type="first">A</forename><surname>Oltramari</surname></persName>
		</author>
		<author>
			<persName><forename type="first">L</forename><forename type="middle">F</forename><surname>Cranor</surname></persName>
		</author>
		<author>
			<persName><forename type="first">R</forename><surname>Walls</surname></persName>
		</author>
		<author>
			<persName><forename type="first">P</forename><surname>Mcdaniel</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">STIDS 2014 (9th International Conference on Semantic Technology for Intelligence</title>
				<imprint>
			<publisher>Defense, and Security</publisher>
			<date type="published" when="2014">2014</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b36">
	<analytic>
		<title level="a" type="main">The WonderWeb Library of Foundational Ontologies and the DOLCE ontology</title>
		<author>
			<persName><forename type="first">C</forename><surname>Masolo</surname></persName>
		</author>
		<author>
			<persName><forename type="first">S</forename><surname>Borgo</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Gangemi</surname></persName>
		</author>
		<author>
			<persName><forename type="first">N</forename><surname>Guarino</surname></persName>
		</author>
		<author>
			<persName><forename type="first">A</forename><surname>Oltramari</surname></persName>
		</author>
		<author>
			<persName><forename type="first">L</forename><surname>Schneider</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Laboratory For Applied Ontology</title>
				<imprint>
			<date type="published" when="2002">2002</date>
		</imprint>
		<respStmt>
			<orgName>ISTC-CNR</orgName>
		</respStmt>
	</monogr>
	<note type="report_type">Technical Report</note>
</biblStruct>

<biblStruct xml:id="b37">
	<analytic>
		<title level="a" type="main">Heterogeneously Structured Ontologies-Integration, Connection, and Refinement</title>
		<author>
			<persName><forename type="first">O</forename><surname>Kutz</surname></persName>
		</author>
		<author>
			<persName><forename type="first">D</forename><surname>Lücke</surname></persName>
		</author>
		<author>
			<persName><forename type="first">T</forename><surname>Mossakowski</surname></persName>
		</author>
	</analytic>
	<monogr>
		<title level="m">Knowledge Representation Ontology. Workshop</title>
				<imprint>
			<date type="published" when="2008">2008</date>
			<biblScope unit="page" from="41" to="50" />
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b38">
	<monogr>
		<title level="m" type="main">Conceptual Spaces: The Geometry of Thought</title>
		<author>
			<persName><forename type="first">P</forename><surname>Gärdenfors</surname></persName>
		</author>
		<imprint>
			<date type="published" when="2004">2004</date>
		</imprint>
	</monogr>
</biblStruct>

<biblStruct xml:id="b39">
	<monogr>
		<title level="m" type="main">Parts: a study on ontology</title>
		<author>
			<persName><forename type="first">P</forename><surname>Simons</surname></persName>
		</author>
		<imprint>
			<date type="published" when="1987">1987</date>
		</imprint>
	</monogr>
</biblStruct>

				</listBibl>
			</div>
		</back>
	</text>
</TEI>
