In the context of improving the effectiveness of knowledge management in intelligent cyber defense systems (ICDS), the task at hand is to organize knowledge based on a cyber-threat ontology using the MITRE ATT&CK and MITRE CAPEC taxonomies, as well as datasets from the European Repository of Cyber Incidents (EuRepoC). The relevance of this is driven by the need for rapid integration of the growing volumes of cyberattack data into the existing semantic core of the ICDS. Moreover, existing approaches to the unification and formalization of heterogeneous data in the cybersecurity domain do not ensure the rapid and controlled integration of new knowledge into the semantic core for the full-fledged formation of a single coherent, semantically interoperable knowledge space; but instead focus exclusively on the superficial consolidation of ontological resources from individual vendors, accompanied by limited scalability and a high level of abstraction, which complicates the representation of cause-and-effect relationships between elements of cyber threats. In this regard, a model of a two-level ontology-based knowledge organization in ICDS has been developed. The essence of the propos
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً