scieee Science in your language
[en] (orig)

Specifying and Verifying Meta-Security by Means of Semantic Web Methods

Abstract

In order to achieve a systematic treatment of security protocols, organizations release a number of technical briefings for describing how security incidents have to be managed. These documents can suffer semantic deficiencies, mainly due to ambiguity or different granularity levels of description and analysis. Ontological Engineering (OE) is a powerful instrument that can be applied for both, cleaning methods and knowledge in incident protocols, and specifying (meta)security requirements on protocols for solving security incidents. We also show how the ontology built from security reports can be used as the knowledge core for semantic systems in order to work with resolution incidents in a safe way. The method has been illustrated with a case study

Read accessible full text

Specifying and Verifying Meta-Security by Means of Semantic Web Methods

Author: Borrego Díaz, Joaquín; Chávez González, Antonia María; Pro Martín, José Luis; Matos Arana, Virginia
Publisher: Springer
Year: 2014
DOI: 10.1007/978-3-319-07995-0_35
Source: https://idus.us.es/bitstreams/20774f0b-95ce-4d02-a9b1-ece8c4f37289/download
Speci ying and Ve i ying Me a-Secu i y
by Means o Seman ic Web Me hods
Joaqu´ın Bo ego-D´ıaz1, An onia M. Ch´a ez-Gonz´alez1,
Jos´eLuis P o-Ma ´ın2, and Vi ginia Ma os-A ana1
1Dep . o Compu e Science and A ificial In elligence – Uni e si y o Se ille, Spain
{jbo ego, cha ez}@us.es, ma−[email p o ec ed]
2Modinem S.L., Se ille, Spain
[email p o ec ed]
Abs ac . In o de o achie e a sys ema ic ea men o secu i y p o o-
cols, o ganiza ions elease a numbe o echnical b iefings o desc ibing
how secu i y inciden s ha e o be managed. These documen s can su -
e seman ic deficiencies, mainly due o ambigui y o diffe en g anula -
i y le els o desc ip ion and analysis. On ological Enginee ing (OE) is a
powe ul ins umen ha can be applied o bo h, cleaning me hods and
knowledge in inciden p o ocols, and speci ying (me a)secu i y equi e-
men s on p o ocols o sol ing secu i y inciden s. We also show how he
on ology buil om secu i y epo s can be used as he knowledge co e
o seman ic sys ems in o de o wo k wi h esolu ion inciden s in a sa e
way. The me hod has been illus a ed wi h a case s udy
1 In oduc ion
A key dimension in Secu i y o In o ma ion Sys ems (SIS) is he documen
gene a ion and managemen . Repo s on inciden s, p o ocols and in o ma ion
on sys ems play a s uc u al ole in he SIS pa adigm. The uni o m iew o
SIS in an o ganiza ion p o ides obus s a egies and secu e sol ing me hods.
Howe e , as i is said in [10], cu en ly he epo s gene ally desc ibe in o ma ion
secu i y policies by a mix o p o essional opinion, s aff expe ience, echnology
manu ac u e ad ice and ex e nal secu i y s anda ds o egula ions.
I could happen hese epo s a e use ul only o membe s o he o ganiza ions
(which sha e he same implici knowledge abou his) o new pa adigms o ces
hem o concilia e managemen me hods.
SIS has e ol ed om a echnical discipline o a s a egic concep . The wo ld’s
g owing dependence on a powe ul bu ulne able In e ne – combined wi h he
dis up i e capabili ies o cybe a acke s – now h ea ens na ional and in e -
na ional secu i y. In [6] he influence ac o s in his pa icula case o secu i y
inciden s is summa ized, showing he complexi y and ha dness o he p oblem.
The po en ially as numbe o dispa a e in o ma ion sou ces makes hei man-
agemen complex and ime-consuming (see also [10]). Al hough such knowledge
Pa ially suppo ed by Excellence p ojec TIC-6064 o Jun a de Andaluc´ıa,co-financed
wi h FEDER ounds.
may be consolida ed by indi idual o ganiza ions, i is ypically kep “in-house”
and he in e ope abili y among diffe en o ganiza ions could be a challenge.
Seman ic Web Technologies (SWT) can p o ide a unified iew o sol e he
abo e-men ioned p oblems. On he one hand, he a emp o o malize he in-
o ma ion desc ibed in he epo s allows o eme ge he knowledge. On he o he
hand, SWT na u ally sol e in e ope abili y p oblems. Tha is, he consensus e -
o o ep esen documen knowledge by means o on ologies and da a o ces
he enginee o achie e he sound unde s anding o ideas, ep esen ed by means
o concep s, p ope ies and axioms o he on ology. Thus he p oblem o unde -
s anding he s uc u e o concep s o an icipa e po en ial ailu es may be sol ed
by he combined wo k o Knowledge enginee s and secu i y expe s.
On ological Enginee ing p o ides ools o analyze impo an ea u es as con-
sis ency, compliance wi h cu en Secu i y S anda ds, and fideli y o he in ended
model [1]. The la e is abou he sound ep esen a ion o some concep s, his
means, whe he he specifica ion ep esen s he in en ions o secu i y expe s
and he e a e no axioms no p ope ies clea ly incompa ible wi h eal concep s.
The e o e, he on ology-based app oach enables he defini ion o secu i y con-
cep s and hei dependencies in an unde s andable way o bo h, humans and
so wa e agen s [11]. Beside consis ency and complexi y, he absence o ep e-
sen a ional anomalies is manda o y [1].
In his pape we ocus he in e es in epo s on inciden p o ocols and secu i y
equi emen s. I has been selec ed as unning example he documen se pub-
lished by Spanish INTECO–CERT ins i u ion1:INTECO’s iden ifica ion and
epo o secu i y inciden o s a egic ope a o s [3] and The ope a o console.
A Basic Guide o C i ical In as uc u e P o ec ion [4]. The fi s one aims o
be a guide in ended o se e as a manual o ac ion epo ing and managemen
ela ed o C i ical In as uc u e and S a egic Ope a o s inciden s h ough he
INTECO-CERT. The second one desc ibes he ac ions ha ope a o s ha e o
pe o m in o de o p o ide an effec i e and efficien esponse o secu i y inci-
den s. The documen s p o ide a s anda dized p o ocol o bo h, effec i ely sol e
and documen secu i y inciden s in a SIS scena io.
Aim o he pape . The aim is o show how o use SWT o analyze and epai
secu i y epo s. I is based on he cons uc ion o an on ology om in o ma ion
con ained in he documen s, showing how he cons uc ion o he on ology i sel
allows o de ec po en ial conflic s in p o ocols, documen a ion and classifica ion.
2 Seman ic Fea u es o Secu i y Documen a ion
A de ailed analysis o he SIS documen s mus be pe o med om diffe en
poin s o iew. I is necessa y o dis inguish be ween classifica ion (iden ifica-
ion o inciden s) o SIS elemen s and he desc ip ion le el o secu i y p o ocols
( o epo ing o sol ing inciden s). The ep esen a ion o hese ea u es should
1Ac onym o spanish Inciden Response Cen e Secu i y
h p://www.in eco.es/home/na ional_communica ions_ echnology_ins i u e/
Fig. 1. S a egy applied o SIS documen s
o p o ide essen ial elemen s (classes and pa icula indi iduals) o he on ol-
ogy. The modula na u e o he on ology should allow o ex end ao modi y
hese elemen s wi hou a gene al econside a ion o on ological commi men s.
To achie e his modula i y, he op le els o he on ology ha e o concilia e bo h
poin s o iew, whils low le el classes will ep esen a se o pa icula elemen s
(usable ac ions, specific p o ocols, a se o possible iden ifica ions and classifi-
ca ions, e c.). Iden ifica ion and p o ocol desc ip ions ha e diffe en on ological
na u e al hough hey sha e some common ea u es which allow o a icula e he
on ology in wo sub-hie a chies.
I would possible o speci y iden ifica ion and esolu ion p o ocols by means
o s anda d se ice on ologies (e.g. OWL-S o WSMO). In his case a specific
flowcha -based on ological desc ip ion o p o ocols is selec ed. The easons o
his choice a e jus ified by he pa icula ea u es o SIS:
•Desc ip ion (a ope a o le el) is simple han s anda d se ice on ologies.
•The ep esen a ion o p o ocols is e y simila o hei na u al (g aphical)
desc ip ions in documen s, making hem easily unde s andable.
•I p o ides a concise seman ic desc ip ion o he p o ocols which does no add
complexi y o easoning se ices.
•Because o na u al mapping be ween ac ions and on ological elemen s, he
addi ion o new ac ions/desc ip ion elemen s does no equi e SWT expe s.
2.1 S a egy o Knowledge Reco e y and Rep esen a ion
The s a egy o on ology ex ac ion consis s o se e al s ages (see Fig. 1):
1. P elimina y analysis
–To s a e he scope and in ended use o SIS documen .
–Documen analysis. On ology enginee s analyze he logical s uc u e o
he documen and isola e main concep s used wi hin.
–To de e mine he on ological na u e o diffe en concep s. Elabo a ion o
a fi s ca ego iza ion (possibly by building se e al hie a chies).
–To find po en ial ambigui ies o deficiencies in elemen s o be included
in he on ology.
2. On ology c ea ion:
–Hie a chies and p ope ies implemen a ion. On ology a icula ion.
–Design o axioms (classes specifica ion) o he key concep s.
–S udy o ela ionships be ween he o me subhie a chies.
3. Compa ison o diffe en (sub)on ologies wi h s anda d secu i y on ologies.
4. Seman ic e alua ion epo (wi h imp o emen p oposals).
Each s ep equi es some discussion on he ea u es o c i ical concep s. The
applicabili y o he on ology as seman ic e e ence o u u e SIS sys ems has o
be aken in o accoun . Due o he lack o space, only he main s eps a e desc ibed
in he pape , specially hose whe e on ological analysis is ele an .
2.2 Rep esen abili y o Secu i y Issues
The p oposed bo om-up app oach is he na u al choice because i is no in-
ended o build a (o he ) secu i y on ology. I aims o build an implici on ology
hidden in epo documen a ion wi hin an o ganiza ion. The o he app oach,
he adop ion o a p e-exis en secu i y on ology o o malize and cla i y he SIS
documen a ion, does no seem a sound app oach o hese goals: Such an on-
ology usually desc ibes an app oach o SIS epo /classifica ion ha can be
incompa ible wi h he implici knowledge in he conc e e o ganiza ion. I ha e
usually been buil on secu i y in o ma ion esou ces, and, since hese kind o
esou ces ha e no been designed o fi on ological s uc u es, se e al deficien-
cies o ep esen a ion a ise. In [5], au ho s de ec a numbe o ep esen a ional
p oblems when en iching a secu i y on ology wi h In o ma ion secu i y:
P1: No concep s o some kind o ulne abili ies
P2: Vague connec ions be ween h ea s and con ols
P3: No ela ionships be ween h ea s
P4: Inconsis en g anula i y o in o ma ion
P5: Redundancy and o e lapping o in o ma ion
The bo om-up ex ac ion o he on ology aid o sol e mos o he abo e-
men ioned p oblems o a pa icula o ganiza ion (p oblems P1,P2,P4,P5) while
p oblem P3 es s explici posed ( o be sol ed by SIS expe s). I is wo hy o
no e ha he adap a ion o a gene al secu i y on ology o his ask is ha d o
au oma e, because some c i e ia o e ision canno be ully o malized.
3 S a egy o Inciden Repo and Iden i ica ion (IRD)
This sec ion is de o ed o commen he main conclusions o he applica ion o
he abo e desc ibed s a egy o IRT documen s [3,4].
Phases o inciden esponse: Acco ding o [3], he desc ip ion o he main
phases in inciden esponse and mi iga ion o isk a e (see Fig. 2, om [3]):
Iden ifica ion (classifica ion), con en ion and mi iga ion, e idence p ese a ion
Fig. 2. Flowcha o ac ion in a secu i y inciden acco ding [3]
and legal conside a ions, documen a ion and eco e y. The elemen s in hese
phases ha e diffe en na u e. On he one hand, classifica ion and iden ifica ion
ha e s a ic na u e while ac ions co espond o p o ocols (non complex plans).
S a ic dimension e sus Dynamic dimension: P elimina y analysis o docu-
men s show ha wo on ological dimensions a e combined. The fi s one e e s
o (s a ical) iden ifica ion o main elemen s. The impo ance o his dimension
in SIS documen s is due o sol ing/ epai ing/mi iga ion me hods ha s ongly
depend on he secu e iden ifica ion. Despi e ha , i is ha d o s a e he complex
ela ionship among diffe en ca ego ies. SIS documen s o en enume a e elemen s
appea ing in a pa icula o ganiza ion. The me hods o en depend on such clas-
sifica ion. Howe e efinemen s o ca ego iza ion aid o speci y he me hods.
The second dimension is abou he desc ip ion o dynamic elemen s o SIS
scena ios, as o example p o ocols and me hods. The desc ip ion o he p o ocol
is mo e p ecise han isk iden ifica ion. This obse a ion sugges s o define p ecise
flowcha -based subon ologies o desc ibe hem.
Fea u es o Desc ip ional on ological le el: The seman ic desc ip ion SIS has
he g ea ad an age o allowing o compa e he INTECO-CERT app oach o
isks wi h o he ela ed classifica ions and/o on ologies, in o de o e alua e i s
soundness. Pa icula ly in e es ing is o conside i s ela ionship wi h he ollow-
ing six gene al ca ego ies o in o ma ion echnology isk [14]. No e ha concep
mapping be ween hese gene al ca ego ies and INTECO-CERT ca ego ies p o-
ides use ul insigh s o en ich he desc ip ion o ac ion classes ela ed wi h hem.
The ela ionship among bo h ca ego ies is depic ed in Fig.3 . The ela ionship

Fig. 3. Desc ip ional class Risk and i s ela ionship wi h ca ego ies om [14]
is ough and i has o be unde s ood as a se o incipien efinemen s o he
on ology. I is in e es ing o highligh some o hem:
–Malicious code and p og ams: The concep con ains Malwa eIn ec ion.
Thus, on ology could be expanded by adding classes o p e en isks. I
equi es p o ec ion a he indi idual and sys em le el.
–Malicious hacking and in usion: con ains Hacking and In asionA ack.
Howe e , INTECO classifica ion also conside s malicious hacking whi ou
in usion (Re usalO Se ice).
–F aud and decep ion: Desc ip ion in [14]:
Va ious o ms o a acks in he o m o spoofing, masque ading, o salami
a acks ha e been used o do damage o p i acy. Social enginee ing is o en
an effec i e means o ob ain illegal access.
Fi s pa ag aph o he desc ip ion co esponds o SocialMalwa e and pa
o Hacking while he second one co espond o SocialEnginee ing.In his
case on ology is mo e specific han ca ego y om [14].
–Misuse and sabo age: Closely ela ed wi h Vulne abili y. I also con ains
PolicyViola ion. The fi s class is one o he unde specified concep s in
INTECO-CERT. The o iginal ca ego y om [14] ep esen s he esou ces
ha can be misused, o andalized h ough unau ho ized access.
–E o s and omissions: Closely ela ed wi h Vulne abili y. Acco ding o
[14], his ca ego y assumes acciden al (so wa e) e o s, o include unin-
ended des uc ion o files o da a, as well as ou ing o ansmission e o s.
This also includes p og amming e o s. Thus i seems ha Vulne abili y
class has no a good le el o g anula i y in INTECO documen .
–Physical and en i onmen al haza d: I is ou o he scope o Risk class o [3].
On ological analysis o his kind o ela ionships among ca ego iza ions can be
used in o he pa s o he on ology, by using ano he ela ed secu i y on ologies.
E en i can induce o dis inguish be ween sa e y and secu i y, in o de o e-
fine on ology in some SIS scena ios [13]. A mo e de ailed isk classifica ion and
desc ip ion needs he o mal inclusion o damage concep . This inclusion would
o ce o efine isk ca ego ies, as in [9]. Also, i is in e es ing o efine concep s
abou cybe a acks om [6]. In his way he inclusion o a ge concep allows
he in oduc ion o new mi iga ion s a egies a dynamic le el.
Dynamic on ological le el. One o he INTECO–CERT/CNPIC asks is he
esponse o secu i y inciden s epo ed as occu ing in C i ical In as uc u es
by use s o his se ice, ensu ing ha he ele an in o ma ion is s o ed. The
desc ip ion o he p ocess ollows he scheme shown in Fig. 2 om [3], which can
be ai ly ep esen ed using he flowcha ep esen a ion. Al hough he e exis s
o he on ological ep esen a ions o flowcha s2, as i was al eady men ioned, a
specific sub on ology is designed o manage hese c i ical elemen s in SIS.
Dynamic dimension o seman ic analysis o SIS guides consis s o flowcha
based ep esen a ion o p o ocols. The e sion o his basic concep on he on ol-
ogy is depic ed in Fig. 4. A singula ea u e o he on ology is he iden ifica ion
be ween A omicAc ion and Flowcha Ac ion classes. This non o hodox equi -
alence is he esul o a g oup discussion among au ho s. On ological dis inc ion
be ween ac ion and ep esen a ion o he ac ion wi hin flowcha s is disca ded.
In his way ac ion class is used in bo h le els.
Al hough he e a e mul iple a ian s o flowcha s (Pe i ne s, ASM cha s and
so on), we can conside he simples one, wi h only wo ypes o nodes (boxes):
Ac ion boxes and Decision boxes. The fi s ones con ain a se o ac ions ha he
use should execu e in ha s a e, he e o e an ac ion box mus ha e one and
only one ou pu pa h. They a e ep esen ed as class Ac ionBox in ou on ology.
The second ones a e Decision boxes whe e he inne ex is a condi ion o be
e ified. The nex cu en s a e depends on he alue a which he condi ion
may be e alua ed. This kind o nodes can ha e mul iple ou pu pa hs. Decision
boxes a e modeled by class DecisionBox in ou on ology. Fig. 5 i is shown
he hie a chy o classes o ou sub-on ology. I can be seen ha Ac ionBox
and DecisionBox a e subclass o a mo e gene ic concep ha we ha e called
Inne Class ( ep esen ing he in e nal nodes o a flowcha ). In his way some
es ic ions on he classes can be added:
Ac ionBox (= 1 hasOu pu Pa h.Pa h),
DecisionBox (≥1hasOu pu Pa h.Pa h)
As i is shown in Fig. 2 some kinds o flowcha s ha e wo special nodes. Those
ha don’ ha e an inpu pa h (i.e. inpu deg ee in he g aph is equal ze o) and
hose ha don’ ha e an ou pu pa h (i.e. oupu deg ee is ze o). This nodes a e
ep esen ed in ou flowcha on ology hanks o S a Box and EndBox classes,
2e.g. www.daml.o g/on ologies/183,www.daml.o g/on ologies/306,
biopo al.bioon ology.o g
Fig. 4. Flowcha as basic elemen in ep esen a ional dimension o he on ology
espec i ely. We can en o ce hese cons ain s making hese classes sub ypes o
Ou pu Pa hBox and Inpu Pa hBox:
Inpu Pa hBox ∃hasInpu Pa h.Pa h,
Ou pu Pa hBox ∃hasOu pu Pa h.Pa h
Thus, an ins ance o Inne Box mus inhe i bo h es ic ions:
Inne Box ∃hasInpu Pa h.Pa h,Inne Box ∃hasOu pu Pa h.Pa h
Some o he key concep s and classes o his on ology (bu no shown in Fig.5)
a e Condi ion and Pa h wi h he usual associa ed seman ics.
The s age o (in e nal) on ology a icula ion allows o build seman ic b idges
among he abo e sub-on ologies. In ac , desc ip ional and dynamic on ologies
sha e concep s o common on ological na u e. This s ep p oduces he efinemen
o he high le el o he on ology.
Wi h espec o on ology popula ion, wo main kinds o indi iduals o on-
ology popula ion can be ex ac ed om documen s (p o ocols and inciden s).
Re ising popula ion me hods o secu i y on ologies also sugges s he need o
ex ending he in o ma ion o he documen .
4 Logical Speci ica ion o Me a-Secu i y in IRD
Specifica ion o he on ology opens he possibili y o including cons ain s ha
would be included in he SIS documen a ion (in na u al language). Some o hem
Fig. 5. Flowcha box elemen class
would allow o moni o ize in eg i y/sa e y cons ain s. Fo example, he sys em
only conside s as de ec ed inciden one o which i has an e idence:
De ec ion ≡∃hasE idence.E idence
Likewise, flowcha seman ic specifica ion allows o ins an ia e p o ocols, mak-
ing each one a comple e and consis en ep esen a ion o a secu i y me hod. In
pa icula , only flowcha s ep esen ing app o ed me hods can be included:
FlowCha (≥1 ep esen s.Ac ion)
whe e Ac ion ≡A omicAc ion P ocedu alAc ion. The absence o classifica-
ion o an inciden is p e en ed by a es ic ion axiom on he p ope y o iginIn:
Inciden (= 1 o iginIn.Risk)
5 Rela ed and Fu u e Wo k
The pape shows how he cons uc ion o on ologies om secu i y epo s -
ins ead o selec ing a s anda d secu i y on ology- habili a es he use o o mal
me hods ha insu e hei sa e y, by cla i ying p ocess and desc ip ions. As i
has been al eady commen ed in he in oduc ion, i is no he goal o build (an-
o he ) on ology on secu i y, nei he i is a goal o ep oduce a s anda d me hod
o ex ac one on ology om a documen . The aim is o exploi he on ology
cons uc ion i sel o cla i y and e ise secu i y epo s. The e o e, he key is he
applica ion o SWT s eps om he documen in o ma ion.
The e alua ion o he o e all p ocess depends on wo key s ages ha , because
o lack o space, ha e no been discussed in his pape . On he one hand, since he
p ocess aims o debug and cla i y secu i y epo s by means hei specifica ions
and on ologies, he e alua ion o he me hod has o be based on he eedback
om he epo au ho . On he o he hand, he seconda y p oduc ( he on ology
i sel ) is e alua ed by compa ing i wi h s anda d on ologies on bo h he same
scope and he in ended use. The soundness o he new on ology is use ul o e ise
he epo i sel . Howe e , he on ologies buil om s anda d secu i y desc ip-
ions a e e y use ul o enhance he beha io o mul i-agen -sys ems o secu i y
issues (see e.g. [8]). Likewise, he igh ela ionship be ween he knowledge con-
ained in he epo and he pe o med one allows o use easoning se ices. This
ea u e needs o a efined classifica ion o diffe en easoning se ices ha will
be desc ibed in a nex pape .