ICAR, a categorical framework to connect vulnerability, threat and asset managements

06/21/2023
by   Arnaud Valence, et al.
0

We present ICAR, a mathematical framework derived from category theory for representing cybersecurity NIST and MITRE's ontologies. Designed for cybersecurity, ICAR is a category whose objects are cybersecurity knowledge (weakness, vulnerability, impacted product, attack technique, etc.) and whose morphisms are relations between this knowledge, that make sense for cybersecurity. Within this rigorous and unified framework, we obtain a knowledge graph capable of identifying the attack and weakness structures of an IS, at the interface between description logics, database theory and cybersecurity. We then define ten cybersecurity queries to help understand the risks incurred by IS and organise their defence.

READ FULL TEXT
research
04/30/2023

Constructing a Knowledge Graph from Textual Descriptions of Software Vulnerabilities in the National Vulnerability Database

Knowledge graphs have shown promise for several cybersecurity tasks, suc...
research
06/02/2017

Knowledge Representation in Bicategories of Relations

We introduce the relational ontology log, or relational olog, a knowledg...
research
07/29/2021

Doctrines, modalities and comonads

Doctrines are categorical structures very apt to study logics of differe...
research
06/09/2009

Toward a Category Theory Design of Ontological Knowledge Bases

I discuss (ontologies_and_ontological_knowledge_bases / formal_methods_a...
research
08/29/2022

Extracting Mathematical Concepts from Text

We investigate different systems for extracting mathematical entities fr...
research
05/09/2023

PSP Framework: A novel risk assessment method in compliance with ISO/SAE-21434

As more cars connect to the internet and other devices, the automotive m...
research
02/07/2019

A Unified Dissertation on Bearing Rigidity Theory

Accounting for the current state-of-the-art, this work aims at summarizi...

Please sign up or login with your details

Forgot password? Click here to reset