<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Developing an Ontology of the Cyber Security Domain</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Leo Obrst</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Penny Chase</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Richard Markeloff</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>The MITRE Corporation</string-name>
          <email>pc@mitre.org</email>
        </contrib>
        <contrib contrib-type="author">
          <string-name>McLean</string-name>
        </contrib>
      </contrib-group>
      <abstract>
        <p>- This paper reports on a trade study we performed to support the development of a Cyber ontology from an initial malware ontology. The goals of the Cyber ontology effort are first described, followed by a discussion of the ontology development methodology used. The main body of the paper then follows, which is a description of the potential ontologies and standards that could be utilized to extend the Cyber ontology from its initially constrained malware focus. These resources include, in particular, Cyber and malware standards, schemas, and terminologies that directly contributed to the initial malware ontology effort. Other resources are upper (sometimes called 'foundational') ontologies. Core concepts that any Cyber ontology will extend have already been identified and rigorously defined in these foundational ontologies. However, for lack of space, this section is profoundly reduced. In addition, utility ontologies that are focused on time, geospatial, person, events, and network operations are briefly described. These utility ontologies can be viewed as specialized super-domain or even mid-level ontologies, since they span many, if not most, ontologies -- including any Cyber ontology. An overall view of the ontological architecture used by the trade study is also given. The report on the trade study concludes with some proposed next steps in the iterative evolution of the Cyber ontology.</p>
      </abstract>
      <kwd-group>
        <kwd>ontology</kwd>
        <kwd>malware</kwd>
        <kwd>cyber</kwd>
        <kwd>trade study</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>I. INTRODUCTION</title>
      <p>This report is a trade study to support the development of a
Cyber ontology. In this section we present the goals of both the
Cyber ontology effort and this report. The following sections
discuss the ontology development methodology and various
ontologies and standards that could be utilized to extend the
Cyber ontology. This report concludes with some proposed
next steps in the iterative evolution of the Cyber ontology.</p>
      <p>
        The ultimate goal of this effort is to develop an ontology of
the cyber security domain, expressed in the OWL language,
that will enable data integration across disparate data sources.
Formally defined semantics will make it possible to execute
precise searches and complex queries. Initially, this effort is
focused on malware. Malware is one of the most prevalent
threats to cyber security, and the MITRE team's work on the
Malware Attribute Enumeration and Characterization (MAEC)
language [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] provides a store of knowledge that can be readily
leveraged.
      </p>
      <p>
        As the scope of the ontology expands, the underlying
conceptual framework will be provided by the Diamond Model
of malicious activity [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], shown in Figure 1. The four corners
of the diamond, Victim, Infrastructure, Capability, and Actor
(the one threatening the victim), account for all the major
dimensions of a malicious cyber threat.
      </p>
      <p>
        Fig. 1. The Diamond Model of malicious activity (from [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]).
      </p>
      <p>The primary goals of this document are to explain the
process followed in developing the Cyber ontology and catalog
the sources upon which it is based. A secondary goal is to
provide a compilation of resources useful for constructing
semantic models in the cyber security domain.</p>
    </sec>
    <sec id="sec-2">
      <title>II. ONTOLOGY DEVELOPMENT METHODOLOGY This section identifies the general methodology employed in the ontology development process, along with the specific methodology used to develop the Cyber ontology.</title>
      <sec id="sec-2-1">
        <title>A. General Methodology</title>
        <p>
          In general, the ontology development methodology
employed here is called a "middle-out" approach. This means
that it contains aspects of top-down analysis and bottom-up
analysis. Bottom-up analysis requires understanding the
semantics of the underlying data sources which are to be
integrated. Top-down analysis requires understanding the
semantics of the end-users who will actually use the resulting
ontology-informed, semantically integrated set of data sources,
i.e., the kinds of questions those end-users want to ask or could
ask, given the enhanced capabilities resulting from the
semantic integration of those data sources (e.g., questions that
require temporal integration or reasoning, as over integrated
timelines of events). See references [
          <xref ref-type="bibr" rid="ref3 ref4 ref5 ref6 ref7 ref8">3-8</xref>
          ].
        </p>
        <p>
          These kinds of analyses result in the development of
competency questions [
          <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
          ]. These are the questions that need
to be asked of the ontology in order to provide the targeted
value to the users. As such, these questions can be viewed as
the queries that need to be executed. These queries, in turn, can
be viewed as a test procedure that indicates when the ontology
development is sufficiently complete for a given stage of
development, i.e., when those queries return results that are
accurate, sufficiently rich, and at the right level of granularity
as judged by a subject matter expert (SME).
        </p>
        <p>Capturing the right competency questions is part of the
requirements analysis phase of ontology development. These
help identify use cases and scenarios. Taken together, the
competency questions, uses cases, and scenarios enable the
requirements to be fleshed out.</p>
        <p>The key to ontology development here is of course an
understanding of the cyber domain, which drives the kinds of
entities, properties, relationships, and potentially rules that will
be needed in the ontology.</p>
      </sec>
      <sec id="sec-2-2">
        <title>B. Specific Methodology</title>
        <p>More specifically, the methodology used for the current
ontology development is based on the following principles,
focused on parsimony and reuse:</p>
        <p>Reuse of existing ontologies: Existing ontologies are
reused where possible. The methodology of reuse consists of
the following steps:</p>
        <p>A. Establish the base of possible existing ontologies in
the domain areas of interest, including foundational,
mid-level, utility, and reference ontologies.</p>
        <p>B. When developing the current Cyber ontology,
incorporate classes and properties (and definitions)
that exist in the best of the ontologies of (A).</p>
        <p>C. When the number of classes and properties
incorporated from a given ontology of (A) into the
Cyber ontology grows large, consider directly
importing the given ontology into the Cyber
ontology, and establishing equivalence relations
between the classes of the (A) ontology and the
classes of the Cyber ontology.</p>
        <p>Harvesting of existing schemas, data dictionaries,
glossaries, standards: Other structured and definitional
resources are used when available, as a form of knowledge
acquisition of the domain. These resources are analyzed for
the kinds of entities, relationships, properties, attributes, and
the range of values for those, expressed in the resource. Where
it makes sense, and as correlated with other Cyber database
schemas and expressed analyst questions and interests (and
their decompositions), these entities, relationships, properties,
and values are incorporated into the Cyber ontology, after
refinement according to ontological engineering principles.</p>
        <p>Keeping it simpler: Where possible, the simpler
ontological approach is chosen. This can mean that, for
example, where the choice is between a 4-D spacetime or a
3D space and time conceptualization, the 3-D conceptualization
is chosen because it is generally simpler for non-ontologists to
understand.</p>
      </sec>
      <sec id="sec-2-3">
        <title>C. Cyber Ontology Architecture</title>
        <p>
          The final product of the ontology development
methodology described above will be an ontology that consists
of a number of modular sub-ontologies, rather than a single,
monolithic ontology. Ontologies can be grouped into three
broad categories of upper, mid-level and domain ontologies,
according to their levels of abstraction [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]:
 Upper ontologies are high-level, domain-independent
ontologies that provide common knowledge bases
from which more domain-specific ontologies may be
derived. Standard upper ontologies are also referred to
as foundational or universal ontologies.
 Mid-level ontologies are less abstract and make
assertions that span multiple domain ontologies.
These ontologies may provide more concrete
representations of abstract concepts found in the upper
ontology. There is no clear demarcation point between
upper and mid-level. Mid-level ontologies also
encompass the set of ontologies that represent
commonly used concepts, such as Time and Location.
These commonly used ontologies are sometimes
referred to as utility ontologies [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
 Doman ontologies specify concepts particular to a
domain of interest and represent those concepts and
their relationships from a domain specific perspective.
Domain ontologies may be composed by importing
mid-level ontologies. They may also extend concepts
defined in mid-level or upper ontologies.
        </p>
        <p>
          These categories and their roles in ontology architecture are
shown in Figure 2, reproduced from [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ]. A further discussion
can be found in [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ].
        </p>
        <p>Upper
Upper</p>
        <p>Upper
Utility</p>
        <p>Mid-Level</p>
        <p>Mid-Level</p>
        <p>Super Domain
Domain</p>
        <p>SuperDomain</p>
        <p>Domain
Domain</p>
        <p>Domain</p>
        <p>Upper
Ontology
Mid-Level
Ontology
Domain</p>
        <p>Ontology</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>III. RESOURCES FOR THE MALWARE AND CYBER</title>
      <p>ONTOLOGIES: ONTOLOGIES, SCHEMAS, AND STANDARDS</p>
      <p>There exist a variety of resources that can lay the
groundwork for a Cyber ontology. This section presents a
survey of those resources that we consider to be particularly
applicable and important. These are not limited to ontologies,
but also include taxonomies, lexica, and schemas.</p>
      <sec id="sec-3-1">
        <title>A. Malware Resources</title>
        <p>
          Published attempts to systematically categorize malware
include one ontology [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] and three descriptive languages
implemented in XML [
          <xref ref-type="bibr" rid="ref1 ref12 ref13">1, 12, 13</xref>
          ]. Also worthy of mention is an
attempt at categorizing malware traits [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ].
        </p>
        <p>XML is a technology for defining text documents for
information exchange, and the structure and content of a
particular type of XML document is dictated by an XML
schema. XML schemas offer enumerations of concepts and
shared vocabularies for specific domains that can be useful as a
basis for ontology development. However, XML schemas do
not define formal semantics for the terms they contain, and are
therefore not equivalent to ontologies.</p>
        <p>1)</p>
      </sec>
      <sec id="sec-3-2">
        <title>Swimmer's Ontology of Malware Classes</title>
        <p>
          A paper by Morton Swimmer [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ] is the only non-trivial
attempt to construct an ontological model of malware that we
could identify. Swimmer's ontology is intended to enable data
exchange between security software products. Swimmer's
taxonomy of malware classes is shown in Figure 4.
        </p>
        <p>Swimmer's malware class hierarchy is relatively simple. It
organizes malware into well-known categories such as Trojan
horse, virus, and worm. This may not be useful for malware
instances that exhibit either behaviors from multiple classes or
novel behaviors not associated with any recognized class.
2) MAEC:</p>
      </sec>
      <sec id="sec-3-3">
        <title>Characterization</title>
        <p>In Swimmer's taxonomy of malware characteristics, all
malware characteristics belong to one of three high-level
classes:
•</p>
        <p>Payload. This is assumed to be programmed with
malicious intent.
• Vector. This defines how the malware is deployed or
spread.
• Obfuscation. Characteristics for evading detection.</p>
        <p>In describing vector characteristics, Swimmer coins the
term "insituacy" to mean "the state the Malware strives to be in
through its actions".</p>
      </sec>
      <sec id="sec-3-4">
        <title>Malware</title>
      </sec>
      <sec id="sec-3-5">
        <title>Attribute and</title>
      </sec>
      <sec id="sec-3-6">
        <title>Enumeration</title>
        <p>MAEC is intended as a language for addressing all known
types, variants, and manifestations of malware. Current
signature-based malware detection techniques identify malware
using a single metadata entity (e.g., a file hash), and MAEC’s
primary goal is to provide a more flexible method for
characterizing malware based on patterns of attributes such as
behaviors, artifacts, and attack patterns. This stands in contrast
with Swimmer’s work, which is focused on predefined
malware families and discernible intent.</p>
        <p>MAEC has a tiered architecture, as shown in Figure 5. At
its lowest level, MAEC strives to portray what an instance of
malware does by describing its actions, such as hardware
accesses and system state changes. A distinction is drawn
between semantics and syntactics by abstracting actions away
from their implementations. This facilitates correlation between
malware instances that do similar things at a low-level but with
different implementations (such as malware targeted at
different platforms).</p>
        <p>MAEC's middle level describes malware behaviors.
Behaviors serve to organize and define the purpose behind
lowlevel actions, whether in groups or as singletons. Behaviors can
represent discrete components of malware functionality at a
level that is useful for analysis, triage, detection, etc.</p>
        <p>MAEC's top level summarizes malware in terms of its
mechanisms. Mechanisms are organized groups of behaviors.
Some examples would be propagation, insertion, and
selfdefense. Since there is likely a low upper bound on the number
of possible mechanisms, they can be useful in understanding
the composition of malware at a very high level.</p>
        <p>
          There are other resources such as the Industry Connections
Security Group (ICSG) Malware Metadata Exchange Format
[
          <xref ref-type="bibr" rid="ref12">12</xref>
          ], and Zeltser's Categories of Common Malware Traits [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ],
which space limitations preclude us from elaborating.
        </p>
      </sec>
      <sec id="sec-3-7">
        <title>B. Languages for Cyber Security Incidents</title>
        <p>
          Howard and Longstaff's seminal work [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ] represents an
early attempt to establish a common language for describing
computer and network security incidents. Since then, industry
and standards organizations have promulgated several
languages for describing computer and network security
incidents. Some of the prominent ones are described below.
These languages all share the goal of facilitating information
sharing across the cyber security community.
        </p>
        <p>
          OpenIOC is an XML format for sharing intelligence related
to cyber security incidents. Intelligence is organized as
Indicators of Compromise (IOCs), which represent patterns
that suggest malicious activity. OpenIOC has been developed
by MANDIANT [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] and offered as an open standard.
MANDIANT's products are widely used by defense
contractors, and consistency with OpenIOC facilitates
processing information from the Defense Industrial Base
(DIB). OpenIOC includes around 30 separate XML schemas
that describe various classes of objects that can be used to
detect suspicious activity, such as MD5 hashes, registry keys,
IP addresses, etc. The OpenIOC schemas are probably the most
comprehensive descriptions of these types of objects available.
The MAEC team incorporated the OpenIOC objects into
MAEC and subsequently the OpenIOC objects formed the
starting point for CybOX objects (CybOX is discussed in
Section III.H).
        </p>
        <p>
          IODEF [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ] is a specification, in the form of an XML
schema, developed by the IETF Extended Incident Handling
(INCH) Working Group of the Internet Engineering Task Force
(IETF) [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. IODEF is an information exchange format for
Computer Security Incident Response Teams (CSIRTs). It also
provides a basis for the development of interoperable tools and
procedures for incident reporting.
        </p>
        <p>
          The VERIS framework [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ] is used by Verizon Business
[
          <xref ref-type="bibr" rid="ref19">19</xref>
          ] to collect security incident data from anyone who
volunteers to submit it. These data are collected using a Web
application [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ]. The goal is to collect data of sufficient
quantity and quality to support statistical analyses. Verizon's
data collection is based on what they refer to as the A4 Threat
Model. In this model, security incidents are regarded as a series
of events where an organization's information assets are
adversely affected. These events have four descriptive
dimensions:
 Agent: Whose actions affected the asset
 Action: What actions affected the asset
 Asset: Which assets were affected
 Attribute: How the asset was affected.
        </p>
        <p>
          The details of the VERIS model are available online in a
Wiki format [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ].
        </p>
      </sec>
      <sec id="sec-3-8">
        <title>C. Attack Patterns and Process Models</title>
        <p>
          The literature offers a number of attempts to create
taxonomies and conceptual models of cyber attacks and attack
patterns. Howard and Longstaff's [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ] attack model is shown
in Figure 6. In their model, an attacker uses a tool to exploit a
vulnerability. This produces an action on a target (which
together comprises an event). The intention is to accomplish
an unauthorized result.
        </p>
        <p>
          A more recent work in a similar vein [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ], presented at the
2007 IEEE International Symposium on Network Computing
and Applications, delineates a model for the attack process
that consists of the following phases:
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Reconnaissance. The search for information about potential victims. Gain Access. Gaining access, at the desired level, to a victim's system.</title>
      <p>Privilege Escalation. Escalate the initial privilege level, as
necessary.</p>
      <p>Victim Exploration. Gaining knowledge of the victim's
system, including browsing files, searching user accounts,
identifying hardware, identifying installed program, and
searching trusted hosts.
</p>
      <p>Principal actions. Taking steps to accomplish the ultimate
objective of the attack, such as installing malicious
software or compromising data integrity.</p>
      <p>
        This model is shown in flowchart form in Figure 7,
reproduced from [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
      </p>
      <p>
        Relevant discussions of attack phases can also be found in
blog postings by Bejtlich [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] and Cloppert [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ].
      </p>
      <p>
        The CAPEC catalog [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ] defines a taxonomy of attack
patterns. The CAPEC catalog currently contains 68 categories
and 400 attack patterns. Attack patterns are modeled after
object-oriented design patterns, and by design they exclude
low-level implementation details. Categories are containers for
related attack patterns. The patterns are more or less aligned
with the top two MAEC layers, and categories roughly
correspond to MAEC mechanisms.
      </p>
      <p>
        The WASC Threat Classification [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] is similar to
CAPEC.
      </p>
      <sec id="sec-4-1">
        <title>D. Foundational Ontologies for the Cyber Ontology</title>
        <p>
          Modeling choices are made in the development of
foundational ontologies that have a downward impact on
midlevel and domain ontologies. We cannot describe some of
these ontological choices here, but invite the reader to see [
          <xref ref-type="bibr" rid="ref9">9</xref>
          ].
        </p>
        <p>
          There are several foundational ontologies that could be
considered for use in the Cyber ontology. These range from
Descriptive Ontology for Linguistic and Cognitive
Engineering (DOLCE) [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ], Basic Formal Ontology (BFO)
[
          <xref ref-type="bibr" rid="ref27">27</xref>
          ], Object-Centered High-Level REference ontology
(OCHRE) [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ], Generic Formal Ontology (GFO) [
          <xref ref-type="bibr" rid="ref29">29</xref>
          ],
Suggested Upper Merged Ontology (SUMO) [
          <xref ref-type="bibr" rid="ref30">30</xref>
          ], Unified
Foundational Ontology (UFO) [
          <xref ref-type="bibr" rid="ref31 ref32">31, 32</xref>
          ], and Cyc/OpenCyc
[
          <xref ref-type="bibr" rid="ref33 ref34 ref35">33-35</xref>
          ].
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>E. Utility Ontologies</title>
        <p>The Cyber ontology will necessarily include concepts from
domains that transcend cyber security, such as notions
concerning people, time, space, and events. Where possible,
the Cyber ontology will import existing ontologies to provide
descriptions of these concepts. In this section we very briefly
catalog the utility ontologies that we would consider for
inclusion in the Cyber ontology.</p>
      </sec>
      <sec id="sec-4-3">
        <title>1) Persons</title>
        <p>
          Modeling the Actor and Victim nodes in Figure 1-1 will
entail an ontological description of persons, their social roles
and relationships, and their relationships to things. Among the
available ontologies that might address this need, we include
Friend Of A Friend (FOAF) [
          <xref ref-type="bibr" rid="ref36">36</xref>
          ], DOLCE Social Objects [
          <xref ref-type="bibr" rid="ref37">37</xref>
          ]
which includes social roles and organizations.
        </p>
      </sec>
      <sec id="sec-4-4">
        <title>2) Time</title>
        <p>
          The Cyber ontology will need to be able to express notions
of time instances and intervals, as well as concepts related to
clock and calendar time. Various theories of the structure of
time have been proposed; see [
          <xref ref-type="bibr" rid="ref38">38</xref>
          ] for a survey. Of particular
interest is Allen's Interval Algebra for temporal reasoning
[
          <xref ref-type="bibr" rid="ref39">39</xref>
          ]. Allen's calculus defines 13 basic relations between two
time intervals.
        </p>
        <p>
          There are two W3C standard ontologies of temporal
concepts, OWL-Time [
          <xref ref-type="bibr" rid="ref40">40</xref>
          ] and time-entry [
          <xref ref-type="bibr" rid="ref41">41</xref>
          ]. They both
provide similar vocabularies for expressing facts about
temporal intervals and instants, while time-entry also includes
the concept of an event. Both ontologies contain object
properties that implement the Allen relations. Also included in
the ontologies are classes and relations for expressing intervals
and instants in clock and calendar terms. Both ontologies
include the concept of a time zone, and a separate global time
zone ontology is available [
          <xref ref-type="bibr" rid="ref42">42</xref>
          ].
        </p>
      </sec>
      <sec id="sec-4-5">
        <title>3) Geospatial</title>
        <p>
          The Cyber ontology may require geospatial concepts to
describe the physical locations of people or infrastructure. See
[
          <xref ref-type="bibr" rid="ref43">43</xref>
          ] for a comprehensive survey of available geospatial
ontologies. Another source of information about geospatial
ontologies is the Spatial Ontology Community of Practice
(SOCoP) [
          <xref ref-type="bibr" rid="ref44">44</xref>
          ]. SOCoP is chartered as a Community of
Practice under the Best Practices Committee of the Federal
CIO Council.
        </p>
        <p>
          The two-dimensional analog to Allen's Interval Algebra for
qualitative spatial representation is the Region Connection
Calculus 8 (RCC-8) [
          <xref ref-type="bibr" rid="ref45">45</xref>
          ], so named because eight basic
relations comprise the calculus. RCC theory can be extended
to support reasoning about regions with indeterminate
boundaries [
          <xref ref-type="bibr" rid="ref46">46</xref>
          ].
        </p>
        <p>
          If it is the case that a significant portion of the geospatial
information to be described by the Cyber ontology is in the
form of text mentions of place names, then the GeoNames
Ontology [
          <xref ref-type="bibr" rid="ref47">47</xref>
          ] may be suitable for inclusion in the ontology.
Although GeoNames does not support RCC-8, it has relations
such as locatedIn, nearby, and neighbor. It is accompanied by
a knowledge base containing 140 million assertions about 7.5
million geographical objects that span the globe. A typical use
for GeoNames is to infer what country a given town, city, or
region is located in.
        </p>
      </sec>
      <sec id="sec-4-6">
        <title>F. Events and Situations</title>
        <p>Events are entities that describe the occurrences of actions
and changes in the real world. Situations represent histories of
action occurrences. In this context at least, situations are not
equivalent to states. Events and situations are dynamic and
challenging to model in knowledge representation systems.</p>
        <p>
          As in the temporal and spatial domains, logic formalisms
have been created for representing and reasoning about events
and situations. These are the event calculus [
          <xref ref-type="bibr" rid="ref48">48</xref>
          ] and situation
calculus [
          <xref ref-type="bibr" rid="ref49">49</xref>
          ]. Both calculi employ the notion of fluents. A
fluent is a condition that can change over time. The main
elements of the event calculus are fluents and actions, and for
the situation calculus they are fluents, actions and situations.
        </p>
        <p>Notions of events and situations are included in several of
the ontologies previously described. DOLCE, GFO, Cyc, and
time-entry all have Event classes. GFO has a class named
History that corresponds to the concept of a situation, and Cyc
has a Situation class. BFO's ProcessualEntity class has
subclasses that correspond closely to events and situations.</p>
        <p>
          Ontologies for events and situations include a DOLCE
extension for descriptions and situations [
          <xref ref-type="bibr" rid="ref50">50</xref>
          ], a proposed
upper event ontology [
          <xref ref-type="bibr" rid="ref51">51</xref>
          ], and an ontology for Linking Open
Descriptions of Events (LODE) [
          <xref ref-type="bibr" rid="ref52">52</xref>
          ].
        </p>
      </sec>
      <sec id="sec-4-7">
        <title>G. Network Operations</title>
        <p>A network operations (NetOps) OWL ontology was
developed in 2009 by MITRE as part of the data strategy
effort supporting the NetOps Community of Interest (COI).
The NetOps ontology includes entities and events, and
represents mission threads of interest to US federal
government network management.</p>
      </sec>
      <sec id="sec-4-8">
        <title>H. Other Cyber Resources</title>
        <p>There are a number of other resources that can be mined
for concepts, abstractions, and relationships between entities
that may be suitable for inclusion in a Cyber ontology.</p>
        <p>
          Common Event Expression (CEE) [
          <xref ref-type="bibr" rid="ref53">53</xref>
          ] is intended to
standardize the way computer events are described, logged,
and exchanged. Some of these events would naturally
correspond to malware actions and behaviors. The CEE
components most relevant to cyber security ontology
development are the Common Dictionary and Event
Expression Taxonomy (CDET). The dictionary defines a
collection of event fields and field value types that are used
throughout CEE to specify the values of properties associated
with specific events. The taxonomy specifies event types.
Examples of event types are user login, service restart,
network connection, privilege elevation, and account creation.
        </p>
        <p>
          A recent foundational schema for the cyber domain is
Cyber Observable Expression (CybOX) [
          <xref ref-type="bibr" rid="ref54">54</xref>
          ]. CybOX is
designed for the specification, capture, characterization and
communication of events or stateful properties observable in
the cyber domain in support of a wide range of use cases.
MAEC and CEE both leverage CybOX for describing cyber
objects, actions, and events. An emerging schema is the
Structured Threat Information Expression (STIX) [
          <xref ref-type="bibr" rid="ref55">55</xref>
          ], which
provides an overarching framework for describing threat
information, including adversaries, tactics, techniques and
procedures (TTPs), incidents, indicators, vulnerabilities, and
courses of actions. Malware is included under the heading of
TTPs. STIX references other schemas and cyber information,
including MAEC, CybOX, CVE, and CPE.
        </p>
        <p>
          Security Content Automation Protocol (SCAP) [
          <xref ref-type="bibr" rid="ref56">56</xref>
          ] is a
suite of specifications that standardize the format and
nomenclature by which security software products
communicate software flaw and security configuration
information. In its current incarnation [
          <xref ref-type="bibr" rid="ref57">57</xref>
          ], SCAP is
comprised of seven specifications:







eXtensible Configuration Checklist Description
Format (XCCDF) [
          <xref ref-type="bibr" rid="ref58">58</xref>
          ], a language for authoring
security checklists/benchmarks and for reporting
results of checklist evaluation.
        </p>
        <p>
          Open Vulnerability and Assessment Language
(OVAL) [
          <xref ref-type="bibr" rid="ref59">59</xref>
          ], a language for representing system
configuration information, assessing machine state,
and reporting assessment results.
        </p>
        <p>
          Open Checklist Interactive Language (OCIL) [
          <xref ref-type="bibr" rid="ref60">60</xref>
          ], a
framework for expressing a set of questions to be
presented to a user and corresponding procedures for
interpreting responses to these questions.
        </p>
        <p>
          Common Platform Enumeration (CPE) [
          <xref ref-type="bibr" rid="ref61">61</xref>
          ], a
nomenclature and dictionary of hardware, operating
systems, and applications.
        </p>
        <p>
          Common Configuration Enumeration (CCE) [
          <xref ref-type="bibr" rid="ref62">62</xref>
          ], a
nomenclature and dictionary of security software
configurations.
        </p>
        <p>
          Common Vulnerabilities and Exposures (CVE) [
          <xref ref-type="bibr" rid="ref63">63</xref>
          ],
a nomenclature and dictionary of security-related
software flaws.
        </p>
        <p>
          Common Vulnerability Scoring System (CVSS) [
          <xref ref-type="bibr" rid="ref64">64</xref>
          ],
an open specification for measuring the relative
severity of software flaw vulnerabilities
        </p>
        <p>
          Of these standards, the ones most germane to developing a
Cyber ontology would be OVAL, CPE, CCE and CVE.
Parmelee [
          <xref ref-type="bibr" rid="ref65">65</xref>
          ] has outlined a semantic framework for these
four standards built upon loosely-coupled modular ontologies.
Parmelee's framework is intended to simplify data
interoperability across automated security systems based on
the OVAL, CPE, CCE and CVE standards.
        </p>
        <p>IV. CYBER ONTOLOGY DEVELOPMENT: NEXT STEPS</p>
        <p>The current Cyber ontology is focused primarily on
malware and some preliminary aspects of the so-called
'diamond model', which includes actors, victims,
infrastructure, and capabilities. Necessarily, more of the
infrastructure and capabilities were developed first; however,
even these are not yet developed to the level of detail that is
warranted, i.e., expanding on behavioral aspects and events, in
particular that are the core of Cyber, would make it more
useful. These are our next steps.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>ACKNOWLEDGMENT</title>
      <p>© 2012, The MITRE Corporation. All Rights Reserved.
The views expressed in this paper are those of the authors
alone and do not reflect the official policy or position of The
MITRE Corporation or any other company or individual.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>MAEC</given-names>
            <surname>- Malware Attribute</surname>
          </string-name>
          Enumeration and Characterization. [Online] http://maec.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Ingle</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Organizing</surname>
          </string-name>
          <article-title>Intelligence to Respond to Network Intrusions and Attacks. Briefing for the DoD Information Assurance Symposium</article-title>
          . Nashville,
          <string-name>
            <surname>TN</surname>
          </string-name>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Fernandéz</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gómez-Pérez</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>and</article-title>
          and
          <string-name>
            <surname>Juristo</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          <article-title>METHONTOLOGY: From Ontological Art to Ontological Engineering</article-title>
          . AAAI97 Workshop on Ontological Engineering, Spring Symposium Series. Stanford University,
          <year>1997</year>
          . pp.
          <fpage>33</fpage>
          -
          <lpage>40</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Fernández</surname>
            <given-names>M.</given-names>
          </string-name>
          et al.
          <article-title>Building a Chemical Ontology Using Methontology and the Ontology Design Environment</article-title>
          .
          <source>IEEE Intelligent Systems. January/February</source>
          <year>1999</year>
          . Vol.
          <volume>14</volume>
          , 1. http://www.aifb.unikarlsruhe.de/Lehrangebot/Sommer2001/SemanticWeb/papers/ch emical_ontology.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Fernández</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Overview of Methodologies for Building Ontologies</article-title>
          . Workshop on Ontologies and
          <article-title>Problem-Solving Methods: Lessons Learned and Future Trends. (IJCAI99)</article-title>
          .
          <source>August</source>
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Gómez-Pérez</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fernández</surname>
          </string-name>
          , M. and
          <string-name>
            <surname>de Vicente</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Towards</surname>
          </string-name>
          <article-title>a Method to Conceptualize Domain Ontologies</article-title>
          .
          <source>ECAI '96Workshop on Ontological Engineering</source>
          . Budapest, Hungary : s.n.,
          <year>1996</year>
          . pp.
          <fpage>41</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Gruninger</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Fox</surname>
            ,
            <given-names>M. S.</given-names>
          </string-name>
          <article-title>Methodology for the design and evaluation of ontologies</article-title>
          . Montreal,
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Uschold</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Gruninger</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Ontologies: Principles, Methods, and</article-title>
          <string-name>
            <surname>Applications.</surname>
          </string-name>
          <year>1996</year>
          . Vol.
          <volume>11</volume>
          ,
          <issue>2</issue>
          , pp.
          <fpage>93</fpage>
          -
          <lpage>136</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Obrst</surname>
            ,
            <given-names>L. Ontological</given-names>
          </string-name>
          <string-name>
            <surname>Architectures</surname>
          </string-name>
          . [ed.]
          <article-title>Johanna Seibt, Achilles Kameas Roberto Poli. Chapter 2 in Part One: Ontology as Technology in the book: TAO - Theory and Applications of Ontology</article-title>
          , Volume
          <volume>2</volume>
          :
          <string-name>
            <given-names>Computer</given-names>
            <surname>Applications</surname>
          </string-name>
          . Springer,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Semy</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pulvermacher</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Obrst</surname>
            ,
            <given-names>L. Toward</given-names>
          </string-name>
          <article-title>the Use of an Upper Ontology for U.S. Government and U.S. Military Domains: An Evaluation</article-title>
          .
          <source>MITRE Technical Report, MTR 04B0000063. November</source>
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Swimmer</surname>
            ,
            <given-names>M. Towards</given-names>
          </string-name>
          <article-title>An Ontology of Malware Classes</article-title>
          .
          <source>[Online] January</source>
          <volume>27</volume>
          ,
          <year>2008</year>
          . http://www.scribd.com/doc/24058261/
          <article-title>Towards-an-</article-title>
          <string-name>
            <surname>Ontology-</surname>
          </string-name>
          ofMalware-Classes.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>IEEE-SA - Industry</surname>
            <given-names>Connections.</given-names>
          </string-name>
          [Online] http://standards.ieee.org/develop/indconn/icsg/malware.html.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <article-title>MANDIANT: Intelligent Information Security</article-title>
          . [Online] http://www.mandiant.com.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Zeltser</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <article-title>Categories of Common Malware Traits</article-title>
          .
          <source>Internet Storm Center Handler's Diairy. [Online] Sept. 25</source>
          ,
          <year>2009</year>
          . http://isc.sans.edu/diary.html?storyid=
          <fpage>7186</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Howard</surname>
            ,
            <given-names>J. D.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Longstaff</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          <article-title>A Common Language for Computer Security Incidents</article-title>
          .
          <source>[Technical Report]. Sandia National Laboratories</source>
          ,
          <year>1998</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>Cover</given-names>
            <surname>Pages Incident</surname>
          </string-name>
          <article-title>Object Description and Exchange Format (IODEF)</article-title>
          . [Online] http://xml.coverpages.org/iodef.html.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>Internet</given-names>
            <surname>Engineering Task Force</surname>
          </string-name>
          . [Online] http://www.ietf.org/.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>VERIS</given-names>
            <surname>Framework</surname>
          </string-name>
          . [Online] https://verisframework.wiki.zoho.com/.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>Verizon</given-names>
            <surname>Business</surname>
          </string-name>
          . [Online] http://www.verizonbusiness.com/.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <article-title>Verizon Incident Classification and Reporting</article-title>
          . [Online] https://www2.icsalabs.com/veris/incidents/new#/welcome.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Gadelrab</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>El Kala</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Deswarte</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          <article-title>Execution Patterns in Automatic Malware and Human-Centric Attacks</article-title>
          .
          <source>IEEE International Symposium on Network Computing and Applications</source>
          .
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>Bejtlich</surname>
          </string-name>
          , R. TaoSecurity: Incident Phases of Compromise.
          <source>[Online] June 6</source>
          ,
          <year>2009</year>
          . http://taosecurity.blogspot.com/
          <year>2009</year>
          /06/incident-phases-ofcompromise.html.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Cloppert</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          [Online] Oct.
          <volume>14</volume>
          ,
          <year>2009</year>
          . http://computerforensics.sans.org/blog/2009/10/14/security
          <article-title>-intelligenceattacking-the-kill-chain/.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>CAPEC - Common Attack Pattern Enumeration</surname>
          </string-name>
          and Characterization. [Online] http://capec.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>The</given-names>
            <surname>Web Application Security Consortium</surname>
          </string-name>
          /Threat Classification. [Online] http://projects.webappsec.org/w/page/13246978/ThreatClassification.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>[26] Laboratory for Applied Ontology - DOLCE. [Online] http://www.loa-cnr.it/DOLCE.html.</mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>Basic</given-names>
            <surname>Formal</surname>
          </string-name>
          <article-title>Ontology (BFO)</article-title>
          . [Online] http://www.ifomis.org/bfo.
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Schneider</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <article-title>How to Build a Foundational Ontology -- The Object-Centered High-level Reference Ontology OCHRE</article-title>
          .
          <source>Proceedings OF THE 26TH Annual German Conference on AI, KI 2003: Advances In Artificial Intelligence</source>
          .
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>General</given-names>
            <surname>Formal</surname>
          </string-name>
          <article-title>Ontology (GFO)</article-title>
          . [Online] http://www.ontomed.de/ontologies/gfo/.
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <surname>Niles</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Pease</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Towards</surname>
          </string-name>
          <article-title>a Standard Upper Ontology</article-title>
          . [ed.]
          <source>Chris Welty and Barry Smith. Proceedings of the 2nd International Conference on Formal Ontology in Information Systems (FOIS-2001)</source>
          .
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <surname>Guizzardi</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wagner</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          <article-title>Some Applications of a Unified Foundational Ontology in Business</article-title>
          . [ed.]
          <source>Michael Rosemann and Peter Green. Ontologies and Business Systems Analysis. IDEA Publisher</source>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <surname>Guizzardi</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wagner</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          <article-title>Towards Ontological Foundations for Agent Modeling Concepts using UFO. Agent-Oriented Information Systems</article-title>
          (AOIS),
          <source>selected revised papers of the Sixth International Bi-Conference Workshop on Agent-Oriented Information Systems</source>
          . Springer-Verlag,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <surname>Cycorp</surname>
          </string-name>
          , Inc. [Online] http://cyc.com/cyc/technology/whatiscyc_dir/whatsincyc.
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <surname>Cycorp</surname>
          </string-name>
          , Inc. [Online] http://cyc.com/cyc.
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>[35] OpenCyc.org. [Online] http://www.opencyc.org/.</mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <article-title>The Friend of a Friend (FOAF) project</article-title>
          . [Online] http://www.foaf-project.
          <source>org/.</source>
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <surname>Masolo</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          et al.
          <source>Social Roles and their Descriptions</source>
          .
          <source>Proceedings of KR'2004</source>
          .
          <year>2004</year>
          . pp.
          <fpage>267</fpage>
          -
          <lpage>277</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [38]
          <string-name>
            <surname>Hayes</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <article-title>A Catalog of Temporal Theories</article-title>
          .
          <source>Technical Report UIUC-BI-AI</source>
          -
          <volume>96</volume>
          -01. s.l. :
          <source>Univerisity of Illinois</source>
          ,
          <year>1996</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [39]
          <string-name>
            <surname>Allen</surname>
            ,
            <given-names>J. F.</given-names>
          </string-name>
          <article-title>Maintaining knowledge about temporal intervals</article-title>
          .
          <source>Communications of the ACM</source>
          .
          <year>1983</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          [40]
          <string-name>
            <surname>Hobbs</surname>
            ,
            <given-names>J. R.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Pan</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          <article-title>An Ontology of Time for the Semantic Web. CM Transactions on Asian Language Processing (TALIP): Special issue on Temporal Information Processing</article-title>
          .
          <year>2004</year>
          . Vol.
          <volume>3</volume>
          ,
          <issue>1</issue>
          , pp.
          <fpage>66</fpage>
          -
          <lpage>85</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          [41]
          <string-name>
            <surname>Pan</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Hobbs</surname>
            ,
            <given-names>J. R.</given-names>
          </string-name>
          <article-title>Time in OWL-S</article-title>
          .
          <source>Proceedings of the AAAI Spring Symposium on Semantic Web Services</source>
          . s.l. : Stanford University,
          <year>2004</year>
          . pp.
          <fpage>29</fpage>
          -
          <lpage>36</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          [42]
          <string-name>
            <given-names>A</given-names>
            <surname>Time Zone</surname>
          </string-name>
          <article-title>Resource in OWL</article-title>
          . [Online] http://www.isi.edu/~hobbs/timezonehomepage.html.
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          [43]
          <string-name>
            <surname>Ressler</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dean</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Kolas</surname>
          </string-name>
          , D. Geospatial Ontology Trade Study. [ed.]
          <source>Terry Janssen, Werner Ceuster Leo Obrst. Ontologies and Semantic Technologies for Intelligence. Amsterdam</source>
          , Berlin, Tokyo, Washington D.C. : IOS Press,
          <year>2010</year>
          , Chapter
          <issue>11</issue>
          , pp.
          <fpage>179</fpage>
          -
          <lpage>212</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          [44]
          <article-title>Spatial Ontology Community of Practice (SOCoP)</article-title>
          . [Online] http://www.socop.org/.
        </mixed-citation>
      </ref>
      <ref id="ref45">
        <mixed-citation>
          [45]
          <string-name>
            <surname>Randall</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cui</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          <article-title>and</article-title>
          and
          <string-name>
            <surname>Cohn</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <article-title>A spatial logic based on regions and connection</article-title>
          .
          <source>Proceedings of the 3rd International Conference on Principles of Knowledge Representation and Reasoning</source>
          . Cambridge, MA,
          <year>1992</year>
          . pp.
          <fpage>165</fpage>
          -
          <lpage>176</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref46">
        <mixed-citation>
          [46]
          <string-name>
            <surname>Gotts</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Cohn</surname>
            and
            <given-names>N.</given-names>
          </string-name>
          <article-title>The 'Egg-Yolk' representation of regions with indeterminate boundaries</article-title>
          . [ed.]
          <string-name>
            <given-names>P.</given-names>
            <surname>Burrough</surname>
          </string-name>
          and
          <string-name>
            <given-names>A. M.</given-names>
            <surname>Frank</surname>
          </string-name>
          .
          <source>Proceedings, GISDATA Specialist Meeting on Geographical Objects with Undetermined Boundaries. Francis Taylor</source>
          ,
          <year>1996</year>
          . pp.
          <fpage>171</fpage>
          -
          <lpage>187</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref47">
        <mixed-citation>
          [47]
          <string-name>
            <given-names>GeoNames</given-names>
            <surname>Ontology - Geo Semantic</surname>
          </string-name>
          Web. [Online] http://www.geonames.org/ontology/documentation.html.
        </mixed-citation>
      </ref>
      <ref id="ref48">
        <mixed-citation>
          [48]
          <string-name>
            <surname>Kowalski</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Sergot</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>A Logic-based Calculus of Events</article-title>
          . New Generation Computing .
          <year>1986</year>
          . Vol.
          <volume>4</volume>
          , pp.
          <fpage>67</fpage>
          -
          <lpage>95</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref49">
        <mixed-citation>
          [49]
          <string-name>
            <surname>Reiter</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <article-title>The frame problem in the situation calculus: a simple solution (sometimes) and a completeness result for goal regression</article-title>
          . [ed.]
          <source>Vladimir Lifshitz</source>
          .
          <article-title>Artificial intelligence and mathematical theory of computation: papers in honour of John McCarthy</article-title>
          . San Diego, CA : Academic Press Professional, Inc.,
          <year>1991</year>
          . pp.
          <fpage>359</fpage>
          -
          <lpage>380</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref50">
        <mixed-citation>
          [50]
          <string-name>
            <surname>Gangemi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Mika</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <article-title>Understanding the Semantic Web through Descriptions and Situations</article-title>
          . Proceedings of CoopIS/DOA/ODBASE.
          <year>2003</year>
          . pp.
          <fpage>689</fpage>
          -
          <lpage>706</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref51">
        <mixed-citation>
          [51]
          <string-name>
            <surname>Kaneiwa1</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Iwazume</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Fukuda</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <article-title>An upper ontology for event classifications and relations</article-title>
          .
          <source>AI'07 Proceedings of the 20th Australian joint conference on Advances in artificial intelligence</source>
          .
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref52">
        <mixed-citation>[52] LODE: Linking Open Descriptions of Events. [Online] http://escholarship.org/uc/item/4pd6b5mh.</mixed-citation>
      </ref>
      <ref id="ref53">
        <mixed-citation>
          [53]
          <string-name>
            <surname>Common Event</surname>
          </string-name>
          <article-title>Expression: CEE, A Standard Log Language for Event Interoperability in Electronic Systems</article-title>
          . [Online] http://cee.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref54">
        <mixed-citation>
          [54]
          <string-name>
            <surname>CybOX - Cyber Observable</surname>
          </string-name>
          Expression. [Online] http://cybox.mitre.org/
        </mixed-citation>
      </ref>
      <ref id="ref55">
        <mixed-citation>
          [55]
          <string-name>
            <surname>STIX-whitepaper</surname>
            <given-names>.</given-names>
          </string-name>
          [Online] http://measurablesecurity.mitre.org/docs/STIX-Whitepaper.pdf
        </mixed-citation>
      </ref>
      <ref id="ref56">
        <mixed-citation>
          [56]
          <string-name>
            <given-names>The</given-names>
            <surname>Security Content Automation Protocol (SCAP) - NIST</surname>
          </string-name>
          . [Online] http://scap.nist.gov/.
        </mixed-citation>
      </ref>
      <ref id="ref57">
        <mixed-citation>
          [57]
          <string-name>
            <surname>Quinn</surname>
            , Waltermire, Johnson, Scarfone,
            <given-names>Banghart.</given-names>
          </string-name>
          <article-title>The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.1 (DRAFT)</article-title>
          .
          <source>Gaithersburg, MD : NIST</source>
          ,
          <year>2011</year>
          .
          <fpage>SP800</fpage>
          -
          <volume>126</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref58">
        <mixed-citation>
          [58]
          <string-name>
            <surname>XCCDF - The eXtensible Configuration Checklist Description Format - The Security Content Automation Protocol (SCAP) - NIST</surname>
          </string-name>
          . [Online] http://scap.nist.gov/specifications/xccdf/.
        </mixed-citation>
      </ref>
      <ref id="ref59">
        <mixed-citation>
          [59]
          <string-name>
            <surname>OVAL - Open Vulnerability</surname>
            and
            <given-names>Assessment</given-names>
          </string-name>
          <string-name>
            <surname>Language</surname>
          </string-name>
          . [Online] http://oval.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref60">
        <mixed-citation>
          [60]
          <string-name>
            <surname>OCIL - The Open Checklist Interactive Language - The Security Content Automation Protocol (SCAP) - NIST</surname>
          </string-name>
          . [Online] http://scap.nist.gov/specifications/ocil/.
        </mixed-citation>
      </ref>
      <ref id="ref61">
        <mixed-citation>
          [61]
          <string-name>
            <surname>CPE - Common Platform Enumeration</surname>
          </string-name>
          . [Online] http://cpe.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref62">
        <mixed-citation>
          [62]
          <string-name>
            <surname>Common Configuration</surname>
          </string-name>
          <article-title>Enumeration (CCE): Unique Identifiers for Common System Configuration Issues</article-title>
          . [Online] http://cce.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref63">
        <mixed-citation>
          [63]
          <string-name>
            <surname>CVE - Common Vulnerabilities</surname>
          </string-name>
          and Exposures. [Online] http://cve.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref64">
        <mixed-citation>
          [64]
          <string-name>
            <surname>Common Vulnerability Scoring</surname>
          </string-name>
          <article-title>System (CVSS-SIG)</article-title>
          . [Online] http://www.first.org/cvss/.
        </mixed-citation>
      </ref>
      <ref id="ref65">
        <mixed-citation>
          [65]
          <string-name>
            <surname>Parmelee</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Toward an Ontology Architecture for CyberSecurity Standards</article-title>
          . George Mason University, Fairfax,
          <string-name>
            <given-names>VA</given-names>
            : Semantic Technologies for Intelligence, Defense, and
            <surname>Security</surname>
          </string-name>
          (STIDS)
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>