Skip to content

tosdanoye/Security-Keywords

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Security-Keywords

This reposiory is a collection of security keywords that have been extracted from relevant security sources (such as the CWE, OWASP, CVE, RFC 4949). Our efforts also include dividing these keywords into four categories of asset, attack/threat, control/mitigation, and implicit categories. We believe there are interesting use cases that can be built on top of these categories.

  1. Asset/Personally Identifiable Information (PII),
  2. Threat (terms related to threats, attacks and vulnerabilities),
  3. Control (terms related to implemented security controls or countermeasures/mitigations), and
  4. Implicit/Indirect (terms that are indirectly related to security and not in the above 3 categories).

Current application of these terms can be found in the classification model we built for identifying security messages: https://marketplace.atlassian.com/plugins/no.tosin.oyetoyan.plugins.jirasecplugin/server/overview and https://bitbucket.org/ootos/jirasecplugin

We envisage further use cases such as:

  1. Risk estimations
  2. Data-Driven Security Board Games
  3. Attack Tree generation from unstructured data sources

If you find this useful, please send me a mail at: "tosin.oyetoyan@gmail.com" and you are very much welcome to contribute to the keywords :-)

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published