Abstract:
With the rapid development of information technology, cyberattacks have become increasingly sophisticated and dynamic, rendering traditional static security ontologies insufficient for effective security protection. To address the limited applicability and poor adaptability of existing cybersecurity ontologies, a plug-in network cybersecurity ontology model (PCSOM) is proposed. The proposed model defines five core security-domain categories and their subcategories, characterizes the structural relationships among key security entities, and provides thirteen types of plug-in interfaces together with their corresponding extension mechanisms. By integrating multi-domain threat intelligence perspectives with existing security frameworks, the model enables more fine-grained and comprehensive security knowledge representation. Furthermore, the combination of ontology technology and plug-in architecture provides enhanced flexibility, scalability, and interoperability, enabling the model to adapt to evolving threat environments. Experimental results demonstrate that PCSOM outperforms three representative cybersecurity ontology models across most evaluation metrics. Specifically, attribute richness, class richness, and average instance count increase by 17.56%, 1.97%, and 159.24%, respectively, indicating the effectiveness and superiority of the proposed ontology framework.