遇见数据集

Data-Driven Vulnerability Ontology

收藏
Zenodo2026-06-18 更新2026-05-26 收录
官方服务:

资源简介:

Overview This ontology represents an enhanced framework for integrating heterogeneous vulnerability data from multiple authoritative cybersecurity sources. The ontology addresses critical limitations in existing theoretical models by ensuring full coherence with real-world database schemas from CVE, CWE, CAPEC, and CPE repositories. Purpose and Scope The Enhanced Vulnerability Ontology provides a unified semantic framework for representing and reasoning about cybersecurity vulnerabilities, weaknesses, attack patterns, and affected products. It serves as a bridge between theoretical ontological models and practical database implementations, enabling comprehensive analysis of security threats across disparate data sources. Key Features Data-Driven Design Systematically validated against actual database schemas from NIST NVD, MITRE CVE, CWE, CAPEC, and CPE repositories Resolves inconsistencies between theoretical frameworks and real-world data structures Ensures direct correspondence between ontological properties and database fields Comprehensive Coverage CVE (Common Vulnerabilities and Exposures): Complete vulnerability information including CVSS metrics, references, and product configurations CWE (Common Weakness Enumeration): Software and system weaknesses with detailed attributes, mitigations, and examples CAPEC (Common Attack Pattern Enumeration and Classification): Attack patterns with execution flows, prerequisites, and consequences CPE (Common Platform Enumeration): Product and platform information for vulnerability mapping Enhanced Modeling Unified CVSS Integration: Consolidated CVSS metrics representation versus fragmented approaches in prior work Structured References: Enhanced reference classification with tags and metadata Hierarchical Organization: Support for CWE categories and CAPEC abstraction levels Complex Relationships: Rich semantic connections between vulnerabilities, weaknesses, and attack patterns Citation For citation use these entry: @inproceedings{Amalfitano2025ADO, title={A Data-Driven Ontology Framework for Integrating Heterogeneous Vulnerability Sources}, author={Domenico Amalfitano and Domenico Benfenati and Davide Landolfi and Antonio Maria Rinaldi and Cristiano Russo and Cristian Tommasino}, booktitle={Proceedings of the Joint Ontology Workshops (JOWO) - Episode XI: The Sicilian Summer under the Etna, co-located with the 15th International Conference on Formal Ontology in Information Systems (FOIS 2025)}, year={2025}, url={https://api.semanticscholar.org/CorpusID:286219260} } Amalfitano, D., Benfenati, D., Landolfi, D., Rinaldi, A.M., Russo, C., & Tommasino, C. (2025). A Data-Driven Ontology Framework for Integrating Heterogeneous Vulnerability Sources. Joint Ontology Workshops.

提供机构:
Zenodo
创建时间:
2025-07-15
二维码
社区交流群
二维码
科研交流群
商业服务