{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T15:43:59Z","timestamp":1767109439622,"version":"build-2065373602"},"reference-count":39,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2019,6,20]],"date-time":"2019-06-20T00:00:00Z","timestamp":1560988800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Knowledge of software security is highly complex since it is quite context-specific and can be applied in diverse ways. To secure software development, software developers require not only knowledge about general security concepts but also about the context for which the software is being developed. With traditional security-centric knowledge formats, it is difficult for developers or knowledge users to retrieve their required security information based on the requirements of software products and development technologies. In order to effectively regulate the operation of security knowledge and be an essential part of practical software development practices, we argue that security knowledge must first incorporate features that specify what contextual characteristics are to be handled, and represent the security knowledge in a format that is understandable and acceptable to the individuals. This study introduces a novel ontology approach for modeling security knowledge with a context-based approach, by which security knowledge can be retrieved, taking the context of the software application at hand into consideration. In this paper, we present our security ontology with the design concepts and the corresponding evaluation process.<\/jats:p>","DOI":"10.3390\/info10060216","type":"journal-article","created":{"date-parts":[[2019,6,20]],"date-time":"2019-06-20T10:49:59Z","timestamp":1561027799000},"page":"216","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Managing Software Security Knowledge in Context: An Ontology Based Approach"],"prefix":"10.3390","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6228-8367","authenticated-orcid":false,"given":"Shao-Fang","family":"Wen","sequence":"first","affiliation":[{"name":"Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology, Gj\u00f8vik 2815, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology, Gj\u00f8vik 2815, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,6,20]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"McGraw, G. (2006). Software Security: Building Security In, Addison-Wesley Professional.","DOI":"10.1109\/ISSRE.2006.43"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/MS.2002.1003450","article-title":"Knowledge management in software engineering","volume":"19","author":"Rus","year":"2002","journal-title":"IEEE Softw."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"319","DOI":"10.1023\/A:1008679010073","article-title":"Case-based knowledge management tools for software development","volume":"4","author":"Henninger","year":"1997","journal-title":"Automated Softw. Eng."},{"key":"ref_4","first-page":"1073","article-title":"A Context-Based Knowledge Management Framework for Software Development","volume":"22","author":"Cheng","year":"2009","journal-title":"Int. J. Comp. Integr. Man."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Fenz, S., and Ekelhart, A. (2009, January 10\u201312). Formalizing information security knowledge. Proceedings of the 4th international Symposium on information, Computer, and Communications Security, Sydney, Australia.","DOI":"10.1145\/1533057.1533084"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Tsoumas, B., and Gritzalis, D. (2006, January 18\u201320). Towards an ontology-based security management. Proceedings of the 20th International Conference on Advanced Information Networking and Applications, Vienna, Austria.","DOI":"10.1109\/AINA.2006.329"},{"key":"ref_7","unstructured":"Br\u00e9zillon, P. (2003). Making context explicit in communicating objects. Communicating with Smart Objects: Developing Technology for Usable Pervasive Computing Systems, ISTE Publishing Company."},{"key":"ref_8","unstructured":"Br\u00e9zillon, P. (2019, March 23). Modeling and Using Context: Past, Present and Future. Available online: http:\/\/ftp.lip6.fr\/lip6\/reports\/2002\/lip6.2002.010.pdf."},{"key":"ref_9","first-page":"223","article-title":"Contextual knowledge sharing and cooperation in intelligent assistant systems","volume":"62","author":"Pomerol","year":"1999","journal-title":"Le Travail Humain"},{"key":"ref_10","first-page":"537","article-title":"Reinforcing shared context to improve collaboration","volume":"19","author":"Araujo","year":"2005","journal-title":"Revue d\u2019Intel. Artif."},{"key":"ref_11","unstructured":"Klemke, R. (2000, January 30\u201331). Context Framework - an Open Approach to Enhance Organisational Memory Systems with Context Modelling Techniques. Proceedings of the Third International Conference on Practical Aspects of Knowledge Management (PAKM2000), Basel, Switzerland."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1108\/03055720810870897","article-title":"Exploring the contextual dimensions of organization from knowledge management perspective","volume":"38","author":"Jafari","year":"2008","journal-title":"VINE"},{"key":"ref_13","unstructured":"Goldkuhl, G., and Braf, E. (2001, January 8\u20139). Contextual knowledge analysis-understanding knowledge and its relations to action and communication. Proceedings of the Second European Conference on Knowledge Management, Bled, Slovenia."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Bishop, M. (2010). A Clinic for\u201d Secure\u201d Programming. IEEE Secur. Priv., 8.","DOI":"10.1109\/MSP.2010.62"},{"key":"ref_15","first-page":"2","article-title":"How large multi-nationals manage their knowledge","volume":"4","author":"Birkenkrahe","year":"2002","journal-title":"Bus. Rev."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Rosa, M.G., Borges, M.R., and Santoro, F.M. (2003). A conceptual framework for analyzing the use of context in groupware. Groupware: Design, Implementation, and Use, Springer.","DOI":"10.1007\/978-3-540-39850-9_26"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1268","DOI":"10.1145\/50087.50089","article-title":"A field study of the software design process for large systems","volume":"31","author":"Curtis","year":"1988","journal-title":"Comm. ACM"},{"key":"ref_18","first-page":"585","article-title":"Being there: Closing the gap between learners sand contextual knowledge using near-world scenarios","volume":"16","author":"Errington","year":"2009","journal-title":"Int. J. Learn."},{"key":"ref_19","unstructured":"Pashler, H., Bain, P.M., Bottge, B.A., Graesser, A., Koedinger, K., McDaniel, M., and Metcalfe, J. (2019, March 23). Organizing Instruction and Study to Improve Student Learning, Available online: https:\/\/files.eric.ed.gov\/fulltext\/ED498555.pdf."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"89","DOI":"10.3233\/SW-2012-0057","article-title":"WebProt\u00e9g\u00e9: A collaborative ontology editor and knowledge acquisition tool for the web","volume":"4","author":"Tudorache","year":"2013","journal-title":"Semant. Web"},{"key":"ref_21","unstructured":"Harris, S., Seaborne, A., and Prud\u2019hommeaux, E. (2019, March 23). SPARQL 1.1 query language. Available online: https:\/\/www.w3.org\/TR\/sparql11-query\/."},{"key":"ref_22","unstructured":"Brank, J., Grobelnik, M., and Mladenic, D. (2015, January 5). A survey of ontology evaluation techniques. Proceedings of the conference on data mining and data warehouses (SiKDD 2005), Ljubljana, Slovenia."},{"key":"ref_23","first-page":"1","article-title":"Approaches, methods, metrics, measures, and subjectivity in ontology evaluation: A survey","volume":"1","author":"Hlomani","year":"2014","journal-title":"Semant. Web Inf. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1006\/knac.1993.1008","article-title":"A translation approach to portable ontology specifications","volume":"5","author":"Gruber","year":"1993","journal-title":"Knowl. Acquisit."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1017\/S0269888900007797","article-title":"Ontologies: Principles, methods and applications","volume":"11","author":"Uschold","year":"1996","journal-title":"Knowl. Eng. Rev."},{"key":"ref_26","unstructured":"Noy, N.F., and McGuinness, D.L. (2001). Ontology Development 101: A Guide to Creating Your First Ontology, Stanford University. Stanford knowledge systems laboratory technical report KSL-01-05 and Stanford medical informatics technical report SMI-2001-0880."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MPRV.2004.1321026","article-title":"Semantic space: An infrastructure for smart spaces","volume":"3","author":"Wang","year":"2004","journal-title":"IEEE Perv. Comp."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1145\/503124.503146","article-title":"Ontology: Applications and design","volume":"45","author":"Gruninger","year":"2002","journal-title":"Commun. ACM"},{"key":"ref_29","unstructured":"Patel, C., Supekar, K., and Lee, Y. OntoGenie: Extracting ontology instances from WWW. Human Language Technology for the Semantic Web and Web Services, Proceedings of the 7th IEEE International Symposium on Wearable Computers ISWC\u201903, White Plains, NY, USA, 21\u201323 October 2003, IEEE."},{"key":"ref_30","unstructured":"Guo, M., and Wang, J.A. (2009, January 5\u20137). An ontology-based approach to model common vulnerabilities and exposures in information security. Proceedings of the ASEE 2009 Southest Section Conference, Marietta, GA, USA."},{"key":"ref_31","unstructured":"Syed, R., and Zhong, H. (2018, January 16\u201318). Cybersecurity Vulnerability Management: An Ontology-Based Conceptual Model. Proceedings of the Twenty-fourth Americas Conference on Information Systems, New Orleans, LA, USA."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1016\/j.scico.2016.01.005","article-title":"Tracing known security vulnerabilities in software repositories\u2013A Semantic Web enabled modeling approach","volume":"121","author":"Alqahtani","year":"2016","journal-title":"Sci. Comp. Prog."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Gyrard, A., Bonnet, C., and Boudaoud, K. (2013, January 13\u201317). The stac (security toolbox: Attacks & countermeasures) ontology. Proceedings of the 22nd International Conference on World Wide Web, Rio de Janeiro, Brazil.","DOI":"10.1145\/2487788.2487869"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Kang, W., and Liang, Y. (2013, January 26\u201329). A security ontology with MDA for software development. Proceedings of the 2013 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), Nanjing, China.","DOI":"10.1109\/CyberC.2013.20"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"168","DOI":"10.1007\/s11633-016-0950-1","article-title":"An ontology-based approach to security pattern selection","volume":"13","author":"Guan","year":"2016","journal-title":"Int. J. Automat. Comp."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Manzoor, S., Vateva-Gurova, T., Trapero, R., and Suri, N. (2018, January 13). Threat Modeling the Cloud: An Ontology Based Approach. Proceedings of the International Workshop on Information and Operational Technology Security Systems, Crete, Greece.","DOI":"10.1007\/978-3-030-12085-6_6"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1504\/IJITST.2013.058295","article-title":"Ontology-based representation of reusable security requirements for developing secure web applications","volume":"5","author":"Salini","year":"2013","journal-title":"Int. J. Intern. Tech. Secur. Trans."},{"key":"ref_38","first-page":"233","article-title":"An Ontology for Secure Web Applications","volume":"9","author":"Busch","year":"2015","journal-title":"Int. J. Softw. Inf."},{"key":"ref_39","first-page":"119","article-title":"Modelling reusable security requirements based on an ontology framework","volume":"41","author":"Lasheras","year":"2009","journal-title":"J. Res. Pract. Inf. Tech."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/10\/6\/216\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T13:00:01Z","timestamp":1760187601000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/10\/6\/216"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,6,20]]},"references-count":39,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2019,6]]}},"alternative-id":["info10060216"],"URL":"https:\/\/doi.org\/10.3390\/info10060216","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2019,6,20]]}}}