Skip to main navigation Skip to search Skip to main content

An Ontological Model of the Phishing Attack Process

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

85 Downloads (Pure)

Abstract

Phishing attacks are common social engineering cyber attacks in which threat actors masquerade as reputable entities to mislead recipients into performing specific actions, such as revealing financial information, system login credentials, or installing malware. Grasping the phishing attack process is crucial to prevent and counteract this type of scam. Although useful, current conceptual models describing phishing attacks do not provide an unambiguous characterization to support human understanding, communication, and computational tasks. They are informal drawings, diagrams, data models, or schemata of application-focused RDF/OWL ontologies. Instead, we approach the problem by leveraging the Unified Foundational Ontology (UFO) and OntoUML modeling language to propose a Phishing Attack Process Ontology (PAPO), making ontological commitments explicit. We show that this ontological model supports risk identification, according to ISO 31000, and satisfies important quality requirements, including domain adequacy, transparency, logical and ontological coherence, generality, as well as the FAIR principles. By providing ontological foundations for the investigation and fight against phishing attacks, PAPO paves the way for rigorous representation of corresponding real-world scenarios and enhanced applications, such as systems interoperability, data modeling, knowledge-based systems, discrete event simulations, design of phishing detection systems, and evaluation of security mechanisms’ effectiveness.
Original languageEnglish
Title of host publicationEnterprise, Business-Process and Information Systems Modeling
Subtitle of host publication26th International Conference, BPMDS 2025, and 30th International Conference, EMMSAD 2025, Vienna, Austria, June 16-17, 2025, Proceedings
EditorsRenata Guizzardi, Luise Pufahl, Arnon Sturm, Han van der Aa
Place of PublicationCham, Switzerland
PublisherSpringer Spektrum
Pages274-289
Number of pages16
ISBN (Electronic)978-3-031-95397-2
ISBN (Print)978-3-031-95396-5
DOIs
Publication statusPublished - 14 Jun 2025
Event26th International Conference, BPMDS 2025 - Vienna, Austria
Duration: 16 Jun 202517 Jun 2025
Conference number: 26
https://www.emmsad.org/home

Publication series

NameLecture Notes in Business Information Processing
PublisherSpringer
Volume558
ISSN (Print)1865-1348
ISSN (Electronic)1865-1356

Conference

Conference26th International Conference, BPMDS 2025
Abbreviated titleBPMDS 2025
Country/TerritoryAustria
CityVienna
Period16/06/2517/06/25
Internet address

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 7 - Affordable and Clean Energy
    SDG 7 Affordable and Clean Energy
  2. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure
  3. SDG 12 - Responsible Consumption and Production
    SDG 12 Responsible Consumption and Production

Keywords

  • 2025 OA procedure
  • Pphishing attack process ontology
  • Unified Foundational Ontology (UFO)
  • OntoUML
  • Phishing attack

Fingerprint

Dive into the research topics of 'An Ontological Model of the Phishing Attack Process'. Together they form a unique fingerprint.
  • The Dual Nature of Organizational Policies

    Weigand, H., Johannesson, P. & Guizzardi, G., 30 Nov 2025, The Practice of Enterprise Modeling: 17th IFIP Working Conference, PoEM 2024, Stockholm, Sweden, December 3-5, 2024. Proceedings. Paja, E., Zdravkovic, J., Kavakli, E. & Stirna, J. (eds.). Cham, Switzerland: Springer, p. 279-294 16 p. (Lecture Notes in Business Information Processing; vol. 538).

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    Open Access
    File
    17 Downloads (Pure)
  • Towards an Ontology of Type-Level Phenomena for System Modeling

    Calhau, R. F., Almeida, J. P. A., Guizzardi, G., Hoffmann, R., Pires, L. F., Logan, J. & Moreira, J. R., 16 May 2025, Research Challenges in Information Science - 19th International Conference, RCIS 2025, Proceedings. Grabis, J., Vos, T. E. J., Escalona, M. J. & Pastor, O. (eds.). Springer, p. 121-139 19 p. (Lecture Notes in Business Information Processing; vol. 547 LNBIP).

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    Open Access
    File
    10 Downloads (Pure)
  • WATCHDOG: An ontology-aWare risk AssessmenT approaCH via object-oriented DisruptiOn Graphs

    Nicoletti, S. M., Hahn, E. M., Fumagalli, M., Guizzardi, G. & Stoelinga, M., 15 Jun 2025, Advanced Information Systems Engineering: 37th International Conference, CAiSE 2025, Vienna, Austria, June 16-20, 2025. Proceedings, Part II. Krogstie, J., Rinderle-Ma, S., Kappel, G. & Proper, H. A. (eds.). Cham, Switzerland: Springer, p. 314-331 18 p. (Lecture Notes in Computer Science; vol. 15702 LNCS).

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    Open Access
    File
    2 Downloads (Pure)

Cite this