Skip to content

Incidence Response and Threat Intelligence Ontology Birds of a Feather group

Notifications You must be signed in to change notification settings

mswimmer/IRTI-Ontology-BoF

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 

Repository files navigation

Welcome to The FIRST Incident Response and Threat Intelligence Ontology BoF page

How to express facts in the threat intelligence and incident response domain.

Mission

The mission of the Birds of a Feather group, founded at the 29th FIRST Conference in San Juan, Puerto Rico held in June 2017, is to flesh out the idea of an industry standard ontology for Threat Intelligence and Incidence Response data. While the initiative is spearheaded by Martin Eian and Morton Swimmer, we welcome all contributors to the discussion and possible coding. After an initial discussion and fleshing out of use-cases, etc., we will need to decide how to move forward to make it a standard.

Our aim is to elevate the current practice from mere data exchange to actionable knowledge exchange. While we have a number of file formats with which to exchange data, these formats do not define the semantics well enough to ensure that the data producer understands how to properly express his/her data and the consumer therefore needs to re-interpret all incoming data, often forced to guess how it has been produced.

The aim is to produce an ontology for Threat Intelligence and Incident Response information that can be used in multiple ways. An ontology can be used to specify how labels are being used in an existing information exchange document or database. Threat information can also be specified 'natively', independent of any format, by reusing W3C RDF as a data model, which is a set of subject-predicate-object triple relationship, and one of the serialization formats (RDF-XML, N3, Turtle) to express the information. For the ontology itself, W3C's OWL ontology language will be used. Lastly, given the ontology and the data expressed in RDF, Description Logics reasoning can be used to infer new information, or check for consistency.

The triple form of semantic information lends itself to implementation in graph databases, which is becoming popular now, and this ontology can leed to better and more consistent implementations of such graph databases.

Furthermore, using reification of individual triples or subgraphs of the semantic data model, the tactical information can be mapped to strategic goals.

We will not be addressing data quality or confidence issues. We also don't need to address data format issues as we intend to reuse the W3C RDF model or map the ontology to data or database fields.

Prior Art

This project is inspired by the ongoing TOSCA project and we anticipate working closely with that team.

Over the years, there have been a number of papers and projects on security (or related) ontologies:

Ontology-like documents and other resources:

Useful conferences and Journals

Use cases

Planned events

Vocamps, etc

Ontology engineering workshops

PoC

Who to interface with

Vendors, tools, etc.

Next steps

About

Incidence Response and Threat Intelligence Ontology Birds of a Feather group

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published