Using ontologies to assist security management

  • Luciana A. F. Martimiano USP
  • Edson dos Santos Moreira USP


Several tools can be used to manage and store security information. These tools generate a great amount of security alerts, which are stored in different formats. This lack of standard and the amount of data make the tasks of the security administrators even harder, because they have to understand, using their tacit knowledge, different security alerts to make correlation and solve security problems. Aiming to assist the administrators in executing these tasks efficiently, this paper presents the main features and contributions of the security incident ontology developed to model, using a unique format, the concepts of the security incident domain.


