Towards a Semantic Web-enabled Knowledge Base to Elicit Security Requirements for Misuse Cases.

Haibo Hu,Dan Yang,Hong Xiang,Li Fu,Chunxiao Ye,Ren Li
DOI: https://doi.org/10.5220/0003588301030112
2011-01-01
Abstract:Eliciting security requirements is critical but hard for non-expert to fulfill an exhaustive analysis on large body of security knowledge. Emerging models in requirements engineering (RE) society release some burden of such difficulty, as well as security ontologies are booming for knowledge sharing and reuse. There exists necessity for the synergy of them, such as utilizing security ontology (So) as the back end of Knowledge Base (KB) for capturing security requirements by using known RE models. Research advances in the Semantic Web (Sw) community provide a common framework of technologies that allows data to be shared and reused across boundaries of various application and community. This paper proposes a knowledge base which is constructed on So and Misuse Case Model (McM), by representing them into Owl., (Web Ontology Language). Semantic rules can be derived from the correlation of So and MCM to be utilized for reasoning and querying security knowledge via Mcm-based requirements elicitation. The proposed KB coordinates So with a specific RE model to facilitate knowledge sharing to be a foundation for eliciting security requirements automatically.
What problem does this paper attempt to address?