DevSecOps for Enterprise Ontology Platforms: Continuous Validation, Security, and Compliance of Semantic Knowledge Systems
Main Article Content
Abstract
Enterprise ontology systems are new platforms that have become the main components of intelligent organizations due to the ability to support semantic interoperability, knowledge integration, and decision-making that is based on AI computing across the heterogeneous enterprise systems. However, with the development of ontologies, and an increase in cybersecurity threats, stringent regulatory imperatives require ontological governance approach to be safe and automated throughout ontology lifecycle. The proposed ontology platform of ontology platforms Secure Semantic DevSecOps Framework (SSDF) in an enterprise is proposed as a stable ontology engineering, automated semantic validation, and security testing, compliance testing and policy-based deployment, which is run as a single pipeline in the proposed paper. It includes ontology version control, automated consistency checking, initial validation in SHACL and subsequent validation in SPARQL, Semantic vulnerability testing, identity and access control, Knowledge graph security, infrastructure as code and continuous compliance auditing, which is consistent with organizational policy and regulatory policy. The AI-based anomaly detection and automated governance systems also maximize semantic integrity, and minimize human effort. By making sure that security and compliance are a critical component of all the software development life, and not an activity performed after the software has been deployed, the ontology model proposed will allow the secure, scalable and survivable development of ontology to be integrated. It may also allow ontology to evolve quickly besides not being able to trade off data quality and semantic consistency or business governance. The framework is a viable platform to establish powerful semantic knowledge systems, that codesigns the digital transformation of organizations, intelligent automation, simplicable AI and interoperable knowledge-based software, which are built upon the cloud-native and hybrid enterprise architects
Article Details
Section
How to Cite
References
[1] M. Iannacone, S. Bohn, G. Nakamura, et al., “Developing an ontology for cyber security knowledge graphs,” in Proc. 10th Annual Cyber and Information Security Research Conference (CISR), New York, NY, USA: ACM, 2015, pp. 1–4, doi: 10.1145/2746266.2746278.
[2] Z. Syed, A. Padia, T. Finin, A. Joshi, and C. Mathews, “UCO: A Unified Cybersecurity Ontology,” in Proc. AAAI Workshop on Artificial Intelligence for Cyber Security, Phoenix, AZ, USA, 2016.
[3] Y. Jia, Y. Qi, H. Shang, R. Jiang, and A. Li, “A practical approach to constructing a knowledge graph for cybersecurity,” Engineering, vol. 4, no. 1, pp. 53–60, Feb. 2018, doi: 10.1016/j.eng.2018.01.004.
[4] E. Kiesling, A. Ekelhart, K. Kurniawan, M. Huber, and E. Weippl, “The SEPSES knowledge graph: An integrated resource for cybersecurity,” in The Semantic Web – ISWC 2019, Lecture Notes in Computer Science, Cham, Switzerland: Springer, 2019, pp. 198–214, doi: 10.1007/978-3-030-30796-7_13.
[5] L. F. Sikos, “OWL ontologies in cybersecurity: Conceptual modeling of cyber-knowledge,” in AI in Cybersecurity. Cham, Switzerland: Springer, 2019, pp. 1–17, doi: 10.1007/978-3-319-98842-9_1.
[6] L. F. Sikos and D. Philp, “Provenance-aware knowledge representation: A survey of data models and contextualized knowledge graphs,” Data Science and Engineering, vol. 5, no. 4, pp. 293–316, Dec. 2020, doi: 10.1007/s41019-020-00118-0.
[7] Z. Liu, Z. Sun, J. Chen, et al., “STIX-based network security knowledge graph ontology modeling method,” in Proc. 3rd International Conference on Geoinformatics and Data Analysis (ICGDA), New York, NY, USA: ACM, 2020, pp. 152–157, doi: 10.1145/3397056.3397083.
[8] A. Piplai, S. Mittal, A. Joshi, et al., “Creating cybersecurity knowledge graphs from malware after action reports,” IEEE Access, vol. 8, pp. 211691–211703, 2020, doi: 10.1109/ACCESS.2020.3039234.
[9] I. Sarhan and M. Spruit, “Open-CyKG: An open cyber threat intelligence knowledge graph,” Knowledge-Based Systems, vol. 233, Art. no. 107524, 2021, doi: 10.1016/j.knosys.2021.107524.
[10] A. Mohamed, G. Abuoda, A. Ghanem, et al., “RDFFrames: Knowledge graph access for machine learning tools,” The VLDB Journal, vol. 30, no. 6, pp. 1009–1035, 2021, doi: 10.1007/s00778-021-00690-5.
[11] Z. Wang, H. Zhu, P. Liu, et al., “Social engineering in cybersecurity: A domain ontology and knowledge graph application examples,” Cybersecurity, vol. 4, no. 1, 2021, doi: 10.1186/s42400-021-00094-6.
[12] K. Kurniawan, A. Ekelhart, E. Kiesling, et al., “KRYSTAL: Knowledge graph-based framework for tactical attack discovery in audit data,” Computers & Security, vol. 115, Art. no. 102828, 2022, doi: 10.1016/j.cose.2022.102828.