<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Towards Ontology-based Cyber Threat Response</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Nikolay Kalinin</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Facultyof ComputationalMathematicsand Cybernetics</institution>
          ,
          <addr-line>Lomonosov MoscowStateUniversity, 119991, GSP-1, 1-52, LeninskiyeGory,Moscow</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>387</fpage>
      <lpage>396</lpage>
      <abstract>
        <p>Response to the threats ofinformation securityin conditions of modernorganizationwith а largeinafrstructure is an areawithemergencyloaded intensityof the datausage. rFo а successlfu exposureand the preventionof computerattacksthe constructionof complex models of the events is required.ln this work, the question of the applicabllity of ontologicalmodels is examinedfor the descriptionof threats.On the basis of workedout appliedontologies,the modelarchitectureof the knowledgebaseis being oefred, the possiЫe practicalscenariosof its use are being examined.The peculiaritiesof this workare the usage of reasoning on the diferent stages of eventhandling and design of knowledge, not only aboutevents but also aboutan informationinfrastructureand its satfey. Thus, the examined semantic technologiescan Ье а base rfo the completesystem of responseto the threatsof inrfomation security.</p>
      </abstract>
      <kwd-group>
        <kwd>Ontology• Reasoning • Cybersecurity• Threatresponse</kwd>
        <kwd>under Creative</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>An area of information security today is especially relevant: the amount of threats
and their destructive capacity grow with every year. Computer attacks are com­
plicated trigger аЫе operations in that it can involve consideraЫe amount of
network nodes now. Intruders use the various techniques of conducting attacks
and concealment of their activities, complicating work of defenders at the same.
In such circumstances, the development of new methods that would Ье applied
in composition with the automated tools of exposure of cyber threats becomes
not simply an interesting scientific task, but also а valuaЫe practical result.</p>
      <p>The traditional approach for the exposure of threats is based on the use of
signatures, namely search of suspicious templates in operating data. The signa­
ture approach is ublquitously used due to the ease and protfiabllity, orfm the
point of view of computing resources. Unfortunately, it has а range of substantial
drbawacks: the signature approach requires consideraЫe eforts on maintenance
of base of signatures in the actual state not being аЫе to expose new types of
threats (zero-day attacks) and does not allow to line up the models of complex
attacks.</p>
      <p>The most popular alternative ofr the signature approach is the usage of meth­
ods of machine learning. А search of threats, which is based on the exposure of
anomalies, behavioral, and statistical analysis, allows us to find
out substan­
tially more dificult</p>
      <p>attacks than the signature approach, but it is not deprived
of the defects.</p>
      <p>Machine learning algorithms results are often
poorly interpretaЫe
thus there are dificulties</p>
      <p>in localization and threat removing. In addition, such
algorithms often require nfie-tuning</p>
      <p>under а correct infrastructure and skilled
support for the timely account of inevitaЫe changes of external terms.
оТ</p>
      <p>
        two indicated approaches we can add and approach on the basis of formal
models. As noted in the work [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] ontology is already one of the xfied
assets of
realization of the large systems of information security because it allows us to use
the experience of wide expert association for
providing of transparency of work
and forecast of results. Tools of exposure threat on the basis of formal models
can allow not only to identify
and classify
threats but also to efectively
produce
reliaЫe and interpreted decisions rfo
      </p>
      <p>their removal. The key advantage of such
tools is а higher level of the used abstractions that provides knowledge system­
atization, decision automation, and allows to ofer to the expert the decisions
with the observance of rfomal</p>
      <p>response procedures.</p>
      <p>One of the proЫems of conceptual models usage in dynamically developing
areas is the laboriousness of knowledge base maintenance in the actual state. But
the wide usage of open and community-supported standards and taxonomies,
such as CVE/NVD 1 or САРЕС 2 allows to avoid the dificulties
related to up­
dating of the knowledge base. On the one side, open and peer-reviewed sources
allow where appropriate to specify</p>
      <p>the terminological base of ontology and on
the other, allow to update the actual filling
of the knowledge base regularly.</p>
      <p>Another unique advantage of using formal
models in cybersecurity is the high
development level of industrial systems for
collecting information
about pro­
tected objects. In modern organization all required information
is already pre­
sented in inventory databases and SIEM systems 3, that consideraЬly simplifies
its integration in the knowledge base.</p>
      <p>In spite of the fact</p>
      <p>that ontology а long ago and successfully used in many
areas, such as genetics and Ьio-medicine, they meet rarely in enterprise solutions
providing information security. The purpose of this work is а demonstration of
wide possiЬilities of an ontological approach for
the development of methods and
tools rfo
reacting to the security threats of the distributed information
infrastruc­
ture. Central directions of our research are the questions related to applicaЬility
and eficiency</p>
      <p>of logical reasoning and also questions related to the conceptual
representation of knowledge about an information infrastructure.</p>
      <p>The brief review of accessiЫe works is given in the second part of this article,
the third part contains а scheme description of the model knowledge base, on
which in fourth part some possiЬilities of ontological approach are demonstrated.
1 https://cve.mitre.org</p>
    </sec>
    <sec id="sec-2">
      <title>2 http://capec.mitre.org</title>
    </sec>
    <sec id="sec-3">
      <title>3 SIEM (Security information</title>
      <p>and event management) - class of the systems carrying
out the centralized collection and analysis of security log</p>
      <p>
        Related Works
The construction of ontological models in information security is conducted al­
ready for more than fiteen years. One of the first bright works in this area is
ontology IDS 4, presented in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. Authors put the aim to show the utility of on­
tology as а model for classifi cation of attacks in the intrusion detection system
underlining their superiority above more used taxonomies due to greater eflxi­
Ьility and the possibllity to work with heterogeneous data. Their result ontology
presented as attack classifi cation framework and described in DAML-OIL [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]
(language predecessor OWL [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]) ontology plugging in more than 190 concepts
and operating with the data got as а result of instrumentation of the Linux
kernel. Note that one of the dignities of the built ontology authors count the un­
amblguity of objects distribution on classes, thus, the same high level of strictness
is arrived at, as well as at reasoning based on the use of taxonomies. Possiblli­
ties of the use of the built model are on example SYN flood attacks and bufer
overoflw. The classifi cation consists of а selection of the most correct class that
would correspond to the happening event.
      </p>
      <p>
        Another classic example of the ontological model usage is presented in the
article [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], in that it is suggested to use the ontology of informatio n security for
annotating functional efatures web of resources. Final ontology appears as seven
sub ontologies and intended for description of security mechanisms such as pro­
tocols, algorithms, and registration data. In а diefrence ofrm IDS of ontology
that is intended for the use in а certain application, the ontology of submit­
ted authors is а general ontology of information security and can Ье used for
annotating any the web of resources.
      </p>
      <p>
        Development of semantic models is directly connected with the use of in­
dustry standards and specification s, so in work [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] OVM ontology based on
taxonomies is presented and standards of corporation MITRE 5 (CVE, CWE,
САРЕС, CVSS) and intended for description of weakness in software products.
The built ontology is one of maiden attempts to Ьind the current standards of
description in а more dificul t and complete model.
      </p>
      <p>
        Other example of the successful use of open dictionaries is described in [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
Ву а basic proЫem at the automated use of such data authors consider а pres­
ence of important information presented as text. The result of their research is
rfamework trained for extraction of relevant content. Extracted entities intercon­
nection between them appears as RDF-triplets on the basis of simple ontology,
complementary of IDS [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] ontology. The final system is integrated into the
inafrstructure of the linked open data (LOD) 6
      </p>
      <p>
        Approach allowing to systematize not only information security but also the
development of ontology process, presented in works [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] and [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. In the first
authors examine methodology of construction of ontology in cybersecurity. The
construction of ontology in their opinion consists of the next stages:
4 IDS - lntrusion detection system
5 https://mitre.org
6 https://lod-cloud.net/
1. Determination of the aims shown in the required queries to the knowledge
base and supposed scenarios of the use.
2. Analysis of existent ontologies of the same subject domain including all valu­
aЫe concepts from them here. If the number of concepts is great authors
recommend to include whole ontology in the complement of the developed
scheme.
3. Addition of connections coming from data with that it is assumed to work
and coming from necessities and existent industry standard.
      </p>
      <p>
        In authors' opinion, ontologies are usually an association of three levels, from
most general, such as DOLCE, at the top level, to the applied ontology [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] ,
this approach gets further development described as lful ontology-framework
CARTELO. The ontology DOLCE- SPRAY is used at the top level, at middle­
level ontology is presented Ьу the ontology of SECCO, plugging in itself the basic
concepts of cybersecurity, the ontology of cyber-operations OSCO complements
at the bottom level.
      </p>
      <p>
        Ву the natural desire of researchers, that in the total got the embodiment
in а number of works, was to overcome one ontology of all traditional scenarios
of the use of concepts of cybersecurity. Thus in work [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] there is an example of
the complex use of ontology made in composition the system of cybersecurity.
The Package-oriented ontology fo r the description of network tracfi of РАСО
is used as а kernel for extraction of knowledge from network tracfi and as an
instrument of classification of tracfi and, together with more general top-level
ontologies (CARTELO), as an interface for analyst work. ln stand experiments
where eficiency of the system was compared rfo the exposure of attacks with
the and without use of ontology advantages of ontological approach were shown.
In the total authors соте to the conclusion that comblnation of high-level on­
tologies and low-level ontologies allows to substantially increase expressiveness
of semantic model, and usage of such models together with traditional tools to
become the basis for the system of decision making, the superior possibllity of
analyst.
      </p>
      <p>
        In works [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] and [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] an example is made not simply constructions of ontol­
ogy, but also developments of the architecture of knowledge base fo r its use. As
basic functional components of the system authors distinguish the component
of incidents handling presented Ьу the bases of incidents and warnings; asset
management component, presented Ьу the base of resources; and the component
of accumulation of knowledge. The last includes the knowledge base of products
and services, the knowledge base of risks, and the knowledge base of counter­
measures that contain knowledge based on the treatment of industry standards.
Ontology, here, is а tool for uniform manipulation of the collected heterogeneous
data.
      </p>
      <p>
        ln [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] authors note that fo rmal representation of knowledge and integration
of information from diefrent sources allows substantially improve quality of ex­
posure and response. ln the article as main scenarios of the use are the search
of relevant records from IDS, collection of information about sowftare, and at­
tempt of determination of malicious activity on the basis of network tracfi and
changes in the system. For the solution of these tasks, authors develop ontology
of STUCO. Its notaЫe fe atures are relative simplicity and realization Ьу means
of JSON- scheme from one side, promotes its practical applicaЬility, but with
other lays on substantial limitations, main fro m that is the impossiЬility of the
logical reasoning mechanism usage
      </p>
      <p>
        The common decision of long-term proЬlem standardization of fo rmats of
cybersecurity-related knowledge lately became language STIX [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], thererfoe no
wonder that the most complex is universal ontology of cybersecurity (UCO),
presented in work [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] is based on exactly its structure. An ofered ontology is
implemented in OWL DL assuming an efective inference allows to extract infor­
mation from all popular industrial dictionaries and assumes the wide spectrum
of scenarios of the use. Meantime its valuaЫe use in practice feasiЫe only after
its adaptation to certain tasks Ьу means of the addition of corresponding applied
ontologies. UCO is the most successful attempt to create а middle-level ontology,
that ofrm one side would possess suficient expressiveness fo r the description of
conceptions of any cybersecurity directions and with other abandoned space for
the claricfiation of bottom level ontologies.
      </p>
      <p>
        In the conclusion of this review, we want to note that in spite of the fact that
ofr the past years substantial results were oЬtained with the area of development
of cybersecurity ontologies many tasks are not solved. PossiЬility of reasoning
is not used even in those works where implementation allows to use them. The
proЫem of extraction of knowledge from the unstructured sources is not fully
resolved although work makes consideraЫe part of analysing such data. Ontolo­
gies do not contained concepts for description of information infras tructure in
the meantime the question of cybersecurity prioritization events is continuously
related to such knowledge. А possiЫe way for eficient infrastructure represen­
tation presented in recent work [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], but valuaЫe ontologies containing both
knowledge about infrastructure and knowledge of information security are yet
to Ье developed.
3
      </p>
      <p>Knowledge Base Architecture
То show the possiЬilities of ontological approach the model knowledge base was
implemented. А terminological constituent (Т - Ьох) of knowledge base is on­
tology of UCO complemented applied with bottom level ontologies. An actual
constituent (А- Вох) plugs operating information (events and incidents of cyber­
security), information about an infrastructure and also information from open
dictionaries and taxonomies.
3.1</p>
      <p>Ontological Model
As said earlier UCO though and is the most complete cybersecurity ontology in
pure form tfis badly for practical application and requires adaptation. As such
adaptation, additional ontologies for the decision of certain tasks were developed.
Ontology of operating information extends and complements such concepts of
UCO as action and observaЫe. Its main task is to provide accordance with other
objects of knowledge base and Ьу operating inrfomation.</p>
      <p>Its key concept is the
event. The event is the universal observed object and parent for allother types,
which represent events in the real world. ln addition, it plugs in description rules
of threats exposure (signatures, anomalies, and others) and sets their accordance
with industry standards, such as а matrix of АТТ&amp;СК[lЗ].</p>
      <p>Ontology of inrfo­
mation infrastructure
is а clarification</p>
      <p>for uco - identity - localidentity that
allowsto determine authentication for</p>
      <p>internal subjects and also essence set of
infrastructure
objects for</p>
      <p>description of endpoints and applications in an infras­
tructure (frequently Ьу the subclasses of uco - observaЫe) and their well-known
and possiЫe connections. Last from</p>
      <p>ontology models is prioritization ontology.</p>
      <p>It is а model for
concepts ofrm</p>
      <p>а conclusion of environmental risk metrics CVSS. lt includes
the environmental risk of CVSS. Requirements to confidentia lity,
availaЬility, integrity, probaЬility are causing damages that hatch on the basis
of data about subject to the risk to the infrastructure.
3.2</p>
      <sec id="sec-3-1">
        <title>Presentation of Operational Information</title>
        <p>ln а model knowledge base operating information appears as events of SIEM
because the systems of this class are the main components of the centralized
security monitoring in enterprise surroundings. From
the point of data view,
SIEM events are the records of compatiЫe format, extracted from
and security tools aggregated in а single database. The format
diferent</p>
        <p>logs
of records is
based on the СуЬох standard (http://cybox.mitre.org), plugged into SТIX. As
а model data, the logs of regular subsystem of audit of OS Linux, logs generated
Ьу Osquery framework</p>
        <p>(https://osquery.io), and logs of firewalls were used.
3.3</p>
      </sec>
      <sec id="sec-3-2">
        <title>Infrastructure Presentation</title>
        <p>lnformation about an infrastructure</p>
        <p>appears in two basic types of objects: end­
point record and network rule. The first
type contains information about а
certain host, such as the installedsowftare,
security policies, criticality of the
processed information etc. The second is an object for
network availaЬilityde­
scription and written down like the rules of firewalls (that make the basic lfiling
of this part of database) with the only exception that except the standard types
of Deny and Allowthe type of Routine is intended for description
beforehand
of
well-known permanent network connections.
eW
4
4.1</p>
        <p>Use Cases</p>
        <p>Attack Classification
will consider the mechanism of attack classicfiation
with the example of
event finding</p>
        <p>out reverse shell on the host, detected Ьу the system of trafic
analysis. lnitiallyan event is а record of SIEM and rule of sensor associated
with it. The task of classification, in this case, can Ье reformulated in terms of
conceptual model as а task of search of the most certain concept for this event
of SIEM would satisfy description of that. The tree of specicfiation of class for
our example is brought around to Fig. 1.</p>
        <p>hasRuleGorup:Persistence</p>
        <p>hasRule:ReverseShellDetection
hasParentProcess: bash
hasParentProcess:WeЫogic
ProcesslUser:ValidUser
ProcessUser:paren!User</p>
        <p>ValidUserActivity</p>
        <p>WebLogicExplatation</p>
        <p>Thus, classicfiation on the basis of reasoning can Ье basis not only for а
decision-making Ьу а man, but also for the acceptance of the automated decision.
ln our example, such solution is automatic lfitration of false positive.
4.2</p>
        <p>Risk Assessment
ln our model, а risk level is estimated in accordance with the second version
CVSS standard. The standard of CVSS is plugged in itself Ьу three types of met­
rics: base, temporal, and environmental. The rfist two metrics are descriptions
of vulnerability presented in ontology as the property hasCVSSScore and can Ье
delivered from the open-source. The third metrics group is intended for bringing
resulting amendments taking into account descriptions of the information envi­
ronment and their calculation makes the most interest. For the calculation of
environmental metrics descriptions of the afected objects are used. So relation
belongSToystem of class Ednpoint allows denfiing requirements for confidential­
ity availaЬility and integrity, coming from properties of the system such as а
type of processed information and degree of criticism. ProbaЬility of indirect
damage settles accounts coming ofrm criticism of the constrained systems and
closeness of aims on the basis of amount of hosts on that the vulneraЫe version</p>
        <p>Atack
Name:WeЫogic Explatation</p>
        <p>Use
RiskScore</p>
        <p>defindeBy
EnvironmentalMetrics</p>
        <p>Vulnerabllity
cvelD: CVE-2020-2283
hasCVSSScore:9.8</p>
        <p>Affect
extractFrom
----L--</p>
        <p>Scope
NumberO!Hosts: 15</p>
        <p>Endpoint
уТре: Server
EndpointlD: 1234</p>
        <p>BelongTo</p>
        <p>
          System
lnformationLevel: К-2
Criticality: Medium
F inding of related information in our model can Ье materialized on the basis
of rules presenting as SPARQL [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] queries. So, rfo example, for the event of
ifnding out а ssh-tunnel the important constrained information is: inrfomation
about а source, information about а purpose, information about prohiЬitive or
permitting such connection rules. Such SPARQL queries must Ье certain for
every type of ev ent at the leve l of the user interface. It is needed to notice that
inrfomation that is required for the automated treatment doesnot fall into а
category constrainedand hatches Ьу meansof mechanismsof ontology.
5
        </p>
        <sec id="sec-3-2-1">
          <title>Conclusions and Directions for uFrther</title>
        </sec>
        <sec id="sec-3-2-2">
          <title>Work</title>
          <p>Within the work the modelof knowledgebase was built to support processes
of responseto the threats of informationsecurity. Stand tests on the basis of
modelscenariosof the use showedpossiЬility ofdeploymentof ontologicalap­
proach in the processof responseto the incidentsof inrfomation security. The
specialattentionat developmentof ontologicalmodelwassparedto description
of informationinfrastructure as modernprocessesof providinginrfomation secu­
rity in large organizationsindissoluЬlyconnectedwith the processesof network
control and eventual devices. Despite the fact that the ontologicalmodelhas
shownits suitaЬility, there is still а long way to go rfo its full use. Firstly, in
work we did not involve the question of possiЬility of thread data processing
and, as а result, the productivity questions,includingquestionsthat are related
to the choice of optimal dialect of OWL for descriptionof model.Secondly, а
fairly primitive modelfor descriЬingnetworkavailaЬility was used, in that the
questionof presenceor incommunication,in fact, is takento the presenceof cor­
respondingrule on the firewall was used.Thirdly, valuaЫe use of the systemis
impossiЫewithout seriousexpansionof types of processedeventsand expansion
of set of conceptsin ontologiesof application layer. Our global aim is to develop
completeontologicalframework rfo support of responseto cyberthreatsand this
researchis only the first step on а path to this aim.</p>
          <p>Aknowledgements. This work is supervisedЬу Nikolay Skvortsov, dFeeral
Research Center Computer Science and Control of the Russian Academy of
Sciences(FRC CSC RAS).</p>
        </sec>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Barnum</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Standardizing cyber threat intelligence information with the structured threat information expression (stix)</article-title>
          .
          <source>Mitre Corporation</source>
          <volume>11</volume>
          ,
          <fpage>1</fpage>
          -
          <lpage>22</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Ben-Asher</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Oltramari</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Erbacher</surname>
            ,
            <given-names>R.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gonzalez</surname>
          </string-name>
          , С.:
          <article-title>Ontology-based adaptive systems of cyber denfese</article-title>
          .
          <source>ln: STIDS. рр. 34-41</source>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Horrocks</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          , et al.:
          <article-title>Daml+oil: А description logic for the semantic web</article-title>
          .
          <source>IEEE Data Eng. Bull</source>
          .
          <volume>25</volume>
          (
          <issue>1</issue>
          ),
          <fpage>4</fpage>
          -
          <lpage>9</lpage>
          (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Iannacone</surname>
          </string-name>
          , М.,
          <string-name>
            <surname>Bohn</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nakamura</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gerth</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , Hufer, К.,
          <string-name>
            <surname>Bridges</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , Ferragut, Е.,
          <string-name>
            <surname>Goodall</surname>
          </string-name>
          , J.:
          <article-title>Developing an ontology for cyber security knowledge graphs</article-title>
          .
          <source>In: Proceedings of the 10th Annual Cyber and Information Security Research Conefrence. рр. 1-4</source>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Joshi</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Lal</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <source>Finin</source>
          , Т.,
          <string-name>
            <surname>Joshi</surname>
          </string-name>
          , А.:
          <article-title>Extracting cybersecurity related linked data rfom text</article-title>
          .
          <source>In: 2013 IEEE Seventh International Conference on Semantic Computing. рр</source>
          .
          <volume>252</volume>
          -
          <fpage>259</fpage>
          . ШЕЕ (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kim</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Luo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , Kang, М.:
          <article-title>Security ontology for annotating resources</article-title>
          .
          <source>In: ОТМ Confederated International Conrfeences" On the Move to Meaninglfu Internet Systems". рр. 1483-1499</source>
          . Springer (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>McGuinness</surname>
            ,
            <given-names>D.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>nVa Harmelen</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , et al.:
          <article-title>Owl web ontology language overview</article-title>
          .
          <source>W3C recommendation</source>
          <volume>10</volume>
          (
          <issue>10</issue>
          ),
          <year>2004</year>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Obrst</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chase</surname>
          </string-name>
          , Р., Markelo,f R.
          <article-title>: Developing an ontology of the cyber security domain</article-title>
          .
          <source>In: STIDS. рр. 49-56</source>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Oltramari</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Cranor</surname>
            ,
            <given-names>L.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Walls</surname>
            ,
            <given-names>R.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McDaniel</surname>
            ,
            <given-names>P.D.</given-names>
          </string-name>
          :
          <article-title>Building an ontology of cyber security</article-title>
          .
          <source>In: STIDS. рр</source>
          .
          <volume>54</volume>
          -
          <fpage>61</fpage>
          .
          <string-name>
            <surname>Citeseer</surname>
          </string-name>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Scarpato</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cilia</surname>
            ,
            <given-names>N.D.</given-names>
          </string-name>
          , Romano, М.:
          <article-title>Reachabllity matrix ontology: А cybersecurity ontology</article-title>
          .
          <source>Applied Artificial Intelligence</source>
          <volume>33</volume>
          (
          <issue>7</issue>
          ),
          <fpage>643</fpage>
          -
          <lpage>655</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Sirin</surname>
          </string-name>
          , Е.,
          <string-name>
            <surname>Parsia</surname>
          </string-name>
          , В.:
          <article-title>Sparql-dl: Sparql query rfo owl-dl</article-title>
          .
          <source>In: OWLED</source>
          . vol.
          <volume>258</volume>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Sokolov</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kupriyanovsky</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Namiot</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sukhomlin</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pokusaev</surname>
          </string-name>
          , О.,
          <string-name>
            <surname>Lavrov</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Volokitin</surname>
          </string-name>
          , У.:
          <article-title>Modern eu research projects and the digital security ontology of europe</article-title>
          .
          <source>International Journal of Open Information Technologies</source>
          <volume>6</volume>
          (
          <issue>4</issue>
          ),
          <fpage>72</fpage>
          -
          <lpage>79</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Strom</surname>
          </string-name>
          , В.Е.,
          <string-name>
            <surname>Applebaum</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Miller</surname>
            ,
            <given-names>D.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nickels</surname>
          </string-name>
          , К.С.,
          <string-name>
            <surname>Pennington</surname>
            ,
            <given-names>A.G.</given-names>
          </string-name>
          , Thomas, С.В.:
          <article-title>Mitre att&amp;ck: Design and philosophy</article-title>
          .
          <source>cTehnical report</source>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Syed</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Padia</surname>
          </string-name>
          , А.,
          <string-name>
            <surname>Finin</surname>
          </string-name>
          , Т.,
          <string-name>
            <surname>Mathews</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
          </string-name>
          , А.:
          <article-title>Uco: А unified cybersecurity ontology</article-title>
          .
          <source>In: Workshops at the Thirtieth AAAI Conference on Artificial Intelligence</source>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Takahashi</surname>
          </string-name>
          , Т.,
          <string-name>
            <surname>Kadobayashi</surname>
          </string-name>
          , У.:
          <article-title>Reference ontology for cybersecurity operational information</article-title>
          .
          <source>The Computer Journal</source>
          <volume>58</volume>
          (
          <issue>10</issue>
          ),
          <fpage>2297</fpage>
          -
          <lpage>2312</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Takahashi</surname>
          </string-name>
          , Т.,
          <string-name>
            <surname>Kadobayashi</surname>
          </string-name>
          , У.,
          <string-name>
            <surname>Fujiwara</surname>
          </string-name>
          , Н.:
          <article-title>Ontological approach toward cybersecurity in cloud computing</article-title>
          .
          <source>In: Proceedings of the 3rd international conference on Security of information and networks. рр. 100-109</source>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Undercofer</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , Joshi, А.,
          <string-name>
            <surname>Pinkston</surname>
          </string-name>
          , J.:
          <article-title>Modeling computer attacks: An ontology for intrusion detection</article-title>
          .
          <source>In: International Workshop on Recent Advances in Intrusion Detection. рр. 113-135</source>
          . Springer (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Wang</surname>
            ,
            <given-names>J.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guo</surname>
          </string-name>
          , М.:
          <article-title>Ovm: an ontology for vulnerabllity management</article-title>
          .
          <source>In: Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies. рр. 1-4</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>