Vladimir Dimitrov

@uni-sofia.bg

Faculty of Mathematics and Informatics
Sofia University "St. Kliment Ohridski"



              

https://researchid.co/cht_co
33

Scopus Publications

Scopus Publications

  • CAPEC ONTOLOGY GENERATOR
    Vladimir Dimitrov

    Sofia University "St. Kliment Ohridski"
    CAPEC is an effort coordinated by MITRE Corporation. Its aim is attack pattern database structured in taxonomies. CAPEC is available as XML document from its project site. CAPEC structure and content are under permanent change and development. It is still not mature database but may be never will.CAPEC, CWE, and CVE are databases devoted to attacks, weaknesses, and vulnerabilities. They refer each other forming a knowledge ecosystem in cybersecurity area.Traditional approach for knowledge presentation as information does not work well with conceptualizations under dynamics of this ecosystem and particularly of CAPEC. In this paper, an alternative approach to CAPEC knowledge presentation is proposed, as ontology. First, CAPEC structure and content are discussed and then ontology structure is introduced. CAPEC as ontology opens doors to ``open world'' concept that is more adequate to ecosystem dynamics.CAPEC ontology is programmatically generated from CAPEC database.CAPEC ontology generator in implemented in Python.

  • Toward Formalization of Software Security Issues
    V. Dimitrov

    Pleiades Publishing Ltd

  • CAPEC ONTOLOGY
    Vladimir Dimitrov

    Sofia University "St. Kliment Ohridski"
    CAPEC is an effort coordinated by MITRE Corporation. Its aim is attack pattern database structured in taxonomies. CAPEC is available as XML document from its project site. CAPEC structure and content are under permanent change and development. It is still not mature database but may be never will.CAPEC, CWE, and CVE are databases devoted to attacks, weaknesses, and vulnerabilities. They refer each other forming a knowledge ecosystem in cybersecurity area.Traditional approach for knowledge presentation as information does not work well with conceptualizations under dynamics of this ecosystem and particularly of CAPEC. In this paper an alternative approach to CAPEC knowledge presentation is proposed, as ontology. First, CAPEC structure and content are discussed and then ontology structure is introduced. CAPEC as ontology opens doors to ``open world'' concept that is more adequate to ecosystem dynamics.

  • CVE (NVD) Ontology


  • CVE (NVD) Ontology Generator


  • IoT Security Issues


  • Technological Considerations on the Legal Regulation in the Use of Robotic Security Assistants


  • SEMANTIC WEB ECOSYSTEM BASED ON CVE (NVD, CPE), CWE AND CAPEC
    Vladimir Dimitrov

    Sofia University "St. Kliment Ohridski"
    CVE (NVD, CPE), CWE and CAPEC are databases in the Cybersecurity area sponsored and maintained by the US government. These are lists (databases) organized in taxonomies where it is appropriate. They contain information about known vulnerabilities, weaknesses and attacks. CVE (NVD, CPE), CWE and CAPEC are the corner stone in many cybersecurity tools.The usage of traditional database systems for the tasks in the cybersecurity require extended knowledge and skills in querying for identification of vulnerabilities, weaknesses and attacks. CVE (NVD, CPE), CWE and CAPEC contain hidden facts and relationships (knowledge) buried in the data. This knowledge can be effectively accessed by the Semantic web tools.The paper presents an approach for transition to the Semantic web of above-mentioned databases. The approach is presented in illustrative way. This means without duplication with information about the contents available for CVE (NVD, CPE), CWE and CAPEC.

  • Classification of software security tools


  • Building an ontology for CWE from the point of view of architectural concept


  • Adapted SANS cybersecurity policies for nist cybersecurity framework


  • CPE ontology


  • CPE ontology generator


  • iRobot robots for education


  • APPLYING THE KNOWLEDGE BASE OF CWE WEAKNESSES IN SOFTWARE DESIGN
    Zh. E. Sartabanova, V. T. Dimitrov, and S. M. Sarsimbayeva

    al-Farabi Kazakh National University

  • Cloud infrastructure for research and education at university of sofia


  • Annotation of CVE descriptions


  • An ontology of top 25 CWEs


  • Research on the development and implementation of augmented reality technologies


  • Modelling of CWEs on the CWE-287 example


  • Multidimensional data analysis with OLAP


  • Clouds of JINR, university of Sofia and INRNE - Current state of the project


  • Multidimensional analysis of data based on OLAP technology


  • Problems of date and time data types in relational model of data


  • Clouds of JINR, University of Sofia and INRNE join together