{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:27:45Z","timestamp":1781105265413,"version":"3.54.1"},"reference-count":42,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,7,1]]},"abstract":"<p>Computer network attacks differ in the motivation of the entity behind the attack, the execution and the end result. The diversity of attacks has the consequence that no standard classification exists. The benefit of automated classification of attacks, means that an attack could be mitigated accordingly. The authors extend a previous, initial taxonomy of computer network attacks which forms the basis of a proposed network attack ontology in this paper. The objective of this ontology is to automate the classification of a network attack during its early stages. Most published taxonomies present an attack from either the attacker's or defender's point of view. The authors\u2019 taxonomy presents both these points of view. The framework for an ontology was developed using a core class, the \u201cAttack Scenario\u201d, which can be used to characterize and classify computer network attacks.<\/p>","DOI":"10.4018\/ijcwt.2012070102","type":"journal-article","created":{"date-parts":[[2013,9,20]],"date-time":"2013-09-20T09:47:04Z","timestamp":1379670424000},"page":"12-25","source":"Crossref","is-referenced-by-count":12,"title":["A Computer Network Attack Taxonomy and Ontology"],"prefix":"10.4018","volume":"2","author":[{"given":"R. P.","family":"van Heerden","sequence":"first","affiliation":[{"name":"CSIR, Pretoria, South Africa & Rhodes University, Grahamstown, South Africa"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"B.","family":"Irwin","sequence":"additional","affiliation":[{"name":"Rhodes University, Grahamstown, South Africa"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"I. D.","family":"Burke","sequence":"additional","affiliation":[{"name":"CSIR, Pretoria, South Africa"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"L.","family":"Leenen","sequence":"additional","affiliation":[{"name":"CSIR, Pretoria, South Africa"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"ijcwt.2012070102-0","unstructured":"Argyraki, K., & Cheriton, D. (2005). Active internet traffic filtering: Real-time response to denial-of-service attacks. In Proceedings of the Advanced Computing System Association\u2019s Annual Technical Conference (USENIX 2005), Anaheim, CA."},{"issue":"2","key":"ijcwt.2012070102-1","first-page":"389","article-title":"State-sponsored crime: The futility of the economic espionage act.","volume":"28","author":"S.Brenner","year":"2006","journal-title":"Houston Journal of International Law"},{"key":"ijcwt.2012070102-2","doi-asserted-by":"publisher","DOI":"10.1080\/03091929.2010.495067"},{"key":"ijcwt.2012070102-3","doi-asserted-by":"publisher","DOI":"10.1007\/s12117-008-9038-9"},{"key":"ijcwt.2012070102-4","unstructured":"Conficker Working Group. (2011). Conficker working group: Lessons learned document. Retrieved November 16, 2012, fromhttp:\/\/www.confickerworkinggroup.org\/wiki\/pmwiki.php\/ANY\/LessonsLearned#toc1"},{"key":"ijcwt.2012070102-5","unstructured":"Cowan, C., Wagle, P., Pu, C., Beattie, S., & Walpole, J. (2000). Buffer overflows: Attacks and defenses for the vulnerability of the decade. In Proceedings of the DARPA Information Survivability Conference and Exposition (DISCEX \u201800) (pp. 119-129). IEEE Computer Society."},{"key":"ijcwt.2012070102-6","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(98)00017-6"},{"key":"ijcwt.2012070102-7","unstructured":"Dede, D. (2010). Apache.org defaced - Security archive case study. Retrieved November 16, 2012, from http:\/\/blog.sucuri.net\/2010\/03\/apache-org-defaced-security-archive-case-study.html"},{"key":"ijcwt.2012070102-8","doi-asserted-by":"crossref","unstructured":"Dickerson, J. E., & Dickerson, J. A. (2000). Fuzzy network profiling for intrusion detection. In Proceedings of the 19th International Conference of the North American Fuzzy Information Processing Society, 2000 (NAFIPS) (pp. 301-306). IEEE Computer Society.","DOI":"10.1109\/NAFIPS.2000.877441"},{"key":"ijcwt.2012070102-9","doi-asserted-by":"publisher","DOI":"10.1109\/MTS.2011.940293"},{"key":"ijcwt.2012070102-10","doi-asserted-by":"crossref","unstructured":"Grant, T., Venter, H., & Eloff, J. (2007). Simulating adversarial interactions between intruders and system administrators using OODA-RR. IN Proceedings of the 2007 annual research conference of the South African institute of computer scientists and information technologists on IT research in developing countries, (SAICSIT 2007) (pp. 46-55). ACM.","DOI":"10.1145\/1292491.1292497"},{"key":"ijcwt.2012070102-11","doi-asserted-by":"publisher","DOI":"10.1006\/knac.1993.1008"},{"key":"ijcwt.2012070102-12","unstructured":"Hansman, S., & Hunt, R. (2003). A taxonomy of network and computer attack methodologies. Master's thesis. Department of Computer Science and Software Engineering University of Canterbury. Retrieved November 16, 2012, from http:\/\/citeseerx.ist.psu.edu\/oai2."},{"key":"ijcwt.2012070102-13","doi-asserted-by":"publisher","DOI":"10.1145\/1290958.1290968"},{"key":"ijcwt.2012070102-14","unstructured":"Karig, D., & Lee, R. (2001). Remote denial of service attacks and countermeasures (Tech. Rep. No. CE-L2001-002). Princeton University, Department of Electrical Engineering."},{"key":"ijcwt.2012070102-15","unstructured":"Krebs, B. (2012). The scrap value of a hacked PC, revisited. Retrieved November 7, 2012, from Krebs on Security: http:\/\/krebsonsecurity.com\/2012\/10\/the-scrap-value-of-a-hacked-pc-revisited\/"},{"key":"ijcwt.2012070102-16","doi-asserted-by":"publisher","DOI":"10.1145\/1227504.1227475"},{"key":"ijcwt.2012070102-17","doi-asserted-by":"crossref","unstructured":"Lau, F., Rubin, S. H., Smith, M. H., & Trajkovic, L. (2000). Distributed denial of service attacks. In Proceedings of the 2000 IEEE International Conference on Systems, Man, and Cybernetics (pp. 2275-2280).","DOI":"10.1109\/ICSMC.2000.886455"},{"key":"ijcwt.2012070102-18","unstructured":"Lewis, J. A. (2002). Assessing the risks of cyber terrorism, cyber war and other cyber threats. Center for Strategic and International Studies. Washington, DC. Retrieved November 16, 2012, from http:\/\/csis.org\/publication\/assessing-risks-cyber-terrorism-cyber-war-and-other-cyber-threats"},{"key":"ijcwt.2012070102-19","doi-asserted-by":"crossref","unstructured":"Lindqvist, U., & Jonsson, E. (1997). How to systematically classify computer security intrusions. In Proceedings of the IEEE Symposium on Privacy and Security (pp. 154-163). Oakland, CA.","DOI":"10.1109\/SECPRI.1997.601330"},{"key":"ijcwt.2012070102-20","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(02)00109-8"},{"key":"ijcwt.2012070102-21","doi-asserted-by":"publisher","DOI":"10.1145\/997150.997156"},{"key":"ijcwt.2012070102-22","unstructured":"Mookhey, K., & Burghate, N. (2004). Detection of SQL injection and cross-site scripting attacks. Symantic. Retrieved November 18, 2012, from http:\/\/www.symantec.com\/connect\/articles\/detection-sql-injection-and-cross-site-scripting-attacks"},{"key":"ijcwt.2012070102-23","unstructured":"Mudge, R. (2011). Live-fire security testing with Armitage and Metasploit. Linux Journal, 2011(205). Retrieved November 18, 2012, from http:\/\/www.linuxjournal.com\/article\/10973"},{"key":"ijcwt.2012070102-24","unstructured":"Myler, C., & Wapping, L. (2011). Phone hacking scandal. News of the World. Retrieved June 10, 2012, from http:\/\/medbib.com\/News_of_the_world"},{"key":"ijcwt.2012070102-25","unstructured":"Neumann, R., & Parker, C. (1989). A summary of computer misuse techniques. In Proceedings of the 12th National Computer Security Conference (pp. 396-407)."},{"key":"ijcwt.2012070102-26","unstructured":"Noy, N., McGuinness, D., et al. (2001). Ontology development 101: A guide to creating your first ontology. Stanford knowledge systems laboratory technical report KSL-01-05 and Stanford medical informatics technical report SMI-2001-0880."},{"key":"ijcwt.2012070102-27","unstructured":"Razvan, R. (2009). Over the SQL injection hacking method. In Proceedings of the 3rd International Conference on Communications and information technology (pp. 116-118). World Scientific and Engineering Academy and Society (WSEAS)."},{"key":"ijcwt.2012070102-28","doi-asserted-by":"crossref","unstructured":"Rounds, M., & Pendgraft, N. (2009). Diversity in network attacker motivation: A literature review. In Proceedings of the 2009 International Conference on Computational Science and Engineering (pp. 319-323). University of Idaho, ID.","DOI":"10.1109\/CSE.2009.178"},{"key":"ijcwt.2012070102-29","unstructured":"Rouse, M. (2006, October). Definition: Social engineering. SearchSecurity. Retrieved November 18, 2002, from http:\/\/searchsecurity.techtarget.com\/definition\/social-engineering"},{"key":"ijcwt.2012070102-30","doi-asserted-by":"publisher","DOI":"10.1023\/B:CRIM.0000037562.42520.d7"},{"key":"ijcwt.2012070102-31","unstructured":"Schwartz, M. J. (2012, July). Who Is anonymous: 10 key facts. InformationWeek Security. Retrieved November 18, 2012, from http:\/\/www.informationweek.com\/security\/attacks\/who-is-anonymous-10-key-facts\/232600322"},{"key":"ijcwt.2012070102-32","unstructured":"Schwartz, N. D., & E., D. (2011). Thieves found Citigroup site an easy entry. Thieves found citigroup site an easy entry. (13 June 2011). The New York Times. Retrieved November 18, 2012, from http:\/\/www.nytimes.com\/2011\/06\/14\/technology\/14security.html?pagewanted=all"},{"key":"ijcwt.2012070102-33","doi-asserted-by":"crossref","unstructured":"Simmonds, A., Sandilands, P., & van Ekert, L. (2004). An ontology for network security attacks. In Proceedings of the Applied computing: Second Asian Applied Computing Conference, AACC 2004(pp. 317-323), Kathmandu, Nepal.","DOI":"10.1007\/978-3-540-30176-9_41"},{"key":"ijcwt.2012070102-34","unstructured":"Specht, S., & Lee, R. (2004). Distributed denial of service: Taxonomies of attacks, tools, and countermeasures. In Proceedings of the 17th International Conference on Parallel and Distributed Computing Systems, Atlanta, GA (pp. 543-550)."},{"key":"ijcwt.2012070102-35","unstructured":"Spitzner, L. (2001). Know your enemy. Parts I, II, III. Retrieved November 18, 2012, fromhttp:\/\/rootprompt.org\/article.php3?article=159"},{"key":"ijcwt.2012070102-36","unstructured":"Taylor, P. A. (2001). Editorial: Hacktivism. The Semiotic Review of Books, 12(1). Retrieved 18 November 2012 from http:\/\/projects.chass.utoronto.ca\/semiotics\/srb\/Hacktivism.html"},{"key":"ijcwt.2012070102-37","unstructured":"Tut\u00e2nescu, I., & Sofron, E. (2003). Anatomy and types of attacks against computer networks. In Proceedings of the 2nd RoEduNet International Conference, Iassi."},{"key":"ijcwt.2012070102-38","unstructured":"Undercoffer, J., Joshi, A., Finin, T., & Pinkston, J. (2004). A target-centric ontology for intrusion detection. In Proceedings of the 18th International Joint Conference on Artificial Intelligence, San Francisco, CA (pp. 9-15)."},{"key":"ijcwt.2012070102-39","doi-asserted-by":"crossref","unstructured":"van Heerden, R. P., Pieterse, H., & Irwin, B. (2012). Mapping the most significant computer hacking events to a temporal computer attack model. In Proceedings of the Human Choice and Computers (HCC10) International Conference: ICT Critical Infrastructures and Society, Amsterdam, Netherlands.","DOI":"10.1007\/978-3-642-33332-3_21"},{"key":"ijcwt.2012070102-40","doi-asserted-by":"publisher","DOI":"10.3844\/jcssp.2007.478.486"},{"key":"ijcwt.2012070102-41","doi-asserted-by":"crossref","unstructured":"Ye, D., Bai, Q., Zhang, M., & Ye, Z. (2008). P2P distributed intrusion detections by using mobile agents. In Proceedings of the Seventh IEEE\/ACIS International Conference on Computer and Information Science, Portland, OR (pp. 259-265).","DOI":"10.1109\/ICIS.2008.21"}],"container-title":["International Journal of Cyber Warfare and Terrorism"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=86073","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,2]],"date-time":"2022-06-02T01:24:57Z","timestamp":1654133097000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/ijcwt.2012070102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2012,7,1]]},"references-count":42,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,7]]}},"URL":"https:\/\/doi.org\/10.4018\/ijcwt.2012070102","relation":{},"ISSN":["1947-3435","1947-3443"],"issn-type":[{"value":"1947-3435","type":"print"},{"value":"1947-3443","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,7,1]]}}}