Published July 1, 2025 | Version v1
Poster Open

A Knowledge Graph-Based Security Auditing Approach

  • 1. School of Internal Audit, Nanjing Audit University
  • 2. Product Assurance, DNV SCPA
  • 3. School of Computing and Information Technology, Great Bay University

Description

This paper proposes a knowledge graph-based security auditing method. By constructing knowledge graphs to perform security vulnerability risk assessments, the proposed method effectively identifies and evaluates potential security threats, in order to enhance the reliability and security of IT services. The approach is carried out in four stages. First, it is required to collect the public exposed vulnerability data and the asset data of the audited IT platform. Next, a knowledge graph is constructed based on the collected data by designing the meta-graph scheme including node type and relation type. Subsequently, graph queries and visualization tools are taken to identify security vulnerability risks, resulting in affected information assets and corresponding vulnerabilities. Finally, based on the identified security vulnerability risks, the risk assessment is conducted by multi-criteria decision analysis to quantify the overall risk level.

Files

eurosp25posters-final10.pdf

Files (697.8 kB)

Name Size Download all
md5:6bce3dd9fd2f8cee55403beaaacd09dd
697.8 kB Preview Download

Additional details

Related works

Is part of
Poster: 10.5281/zenodo.16758609 (DOI)