An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
32 CHAPTER 5. ONTOLOGY<br />
Person<br />
name<br />
private address<br />
private phone<br />
Name<br />
Address<br />
PhoneNumber<br />
first name last name title street city<br />
street number zip code area code phone number<br />
Text<br />
Number<br />
Figure 5.1: Address book ontology<br />
the characteristics of the concepts. In the address book example the rst<br />
and last name are properties of the class name and street, city and zip code<br />
are properties of the address. The restrictions constra<strong>in</strong> the applicability of<br />
the properties. The properties can be thought of as the edges that connect<br />
the nodes of a directed graph. The restrictions limit what types of edges<br />
are allowed between what types of nodes. In the example it would not make<br />
any sense if the edge that represents the property <strong>for</strong> the rst name would<br />
be allowed to connect nodes of the type address and person. One possibility<br />
<strong>for</strong> the address book ontology is shown <strong>in</strong> gure 5.1. <strong>An</strong> <strong>in</strong>stance of the<br />
structure of the example ontology that describes the address book entry of<br />
a specic person may look similar to gure 5.2.<br />
P1<br />
Person<br />
name<br />
private address<br />
private phone<br />
Nm1<br />
Name<br />
A1<br />
Address<br />
PN1<br />
PhoneNumber<br />
last name<br />
title<br />
first name<br />
city<br />
street<br />
zip code<br />
street number<br />
phone number area code<br />
Doe<br />
Dr<br />
John<br />
Sampleville<br />
Samplestreet<br />
0815<br />
42<br />
0690<br />
555<br />
type<br />
type type<br />
type<br />
type<br />
type type<br />
type<br />
type<br />
Text<br />
Number<br />
Figure 5.2: Address book <strong>in</strong>stance