Skip to main content
QUICK REVIEW

[论文解读] An Ontology-Based Approach to Security Risk Identification of Container Deployments in OT Contexts

Yannick Landeck, Dian Balta|arXiv (Cornell University)|Jan 7, 2026
Software System Performance and Reliability被引用 0
一句话总结

论文提出了容器安全风险本体论(CSRO),一种基于模型、本体驱动的可重复且可互操作的OT容器部署安全风险识别方法,通过案例研究和集成风险识别工具演示。

ABSTRACT

In operational technology (OT) contexts, containerised applications often require elevated privileges to access low-level network interfaces or perform administrative tasks such as application monitoring. These privileges reduce the default isolation provided by containers and introduce significant security risks. Security risk identification for OT container deployments is challenged by hybrid IT/OT architectures, fragmented stakeholder knowledge, and continuous system changes. Existing approaches lack reproducibility, interpretability across contexts, and technical integration with deployment artefacts. We propose a model-based approach, implemented as the Container Security Risk Ontology (CSRO), which integrates five key domains: adversarial behaviour, contextual assumptions, attack scenarios, risk assessment rules, and container security artefacts. Our evaluation of CSRO in a case study demonstrates that the end-to-end formalisation of risk calculation, from artefact to risk level, enables automated and reproducible risk identification. While CSRO currently focuses on technical, container-level treatment measures, its modular and flexible design provides a solid foundation for extending the approach to host-level and organisational risk factors.

研究动机与目标

  • 解决OT容器部署中的安全风险识别挑战(混合IT/OT、利益相关者知识差距、持续变更)。
  • 开发可重复、可解释、并在技术上整合的OT容器风险识别方法。
  • 创建将对手行为、情境、攻击场景、风险规则和容器制品联系起来的容器安全风险本体论(CSRO) 。
  • 通过案例研究和集成的风险识别工具展示该方法,以实现自动化处置。

提出的方法

  • 将CSRO开发为符合OWL 2和RDF标准的知识图谱。
  • 整合五个领域:ATT&CK 技术、情境情景、攻击情景、风险评估规则、容器安全制品。
  • 将容器部署特征与ATT&CK 技术通过语义关系建立联系,以实现自动化推理。
  • 使用SPARQL查询从实例化的CSRO知识图谱计算风险水平。
  • 遵循设计科学研究过程,进行三轮迭代以改进伪器并演示端到端的风险识别。
Figure 1. Overview of our ontology-based approach to complement risk assessment for container deployments in OT contexts using the Container Security Risk Ontology (CSRO) and an integrated risk identification tool.
Figure 1. Overview of our ontology-based approach to complement risk assessment for container deployments in OT contexts using the Container Security Risk Ontology (CSRO) and an integrated risk identification tool.

实验结果

研究问题

  • RQ1如何在OT情境下实现容器部署的可重复、可解释、并在技术上整合的安全风险识别?
  • RQ2CSRO如何设计以将对手行为、情境假设、攻击情景、风险规则与容器制品联系起来,以支持自动化风险识别?

主要发现

  • CSRO整合五个领域,支持OT容器的结构化风险识别。
  • 实例化的CSRO知识图谱通过专用工具实现自动化风险识别与处置推导。
  • 该方法通过语义关系和规则将容器部署特征与MITRE ATT&CK 技术相连。
  • 使用SPARQL查询在CSRO知识图谱上演示自动化风险计算。
  • 设计具有模块化和可扩展性,支持未来的主机级和组织层面的风险因素。
  • 案例研究利用真实世界的OT部署制品和标准(如NIST、CIS)来支撑本体并支持合规性评估。
Figure 2. Overview of the five domains of our Container Security Risk Ontology (CSRO)
Figure 2. Overview of the five domains of our Container Security Risk Ontology (CSRO)

更好的研究,从现在开始

从论文设计到论文写作,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。