TY - GEN
T1 - An Ontological Model of the Phishing Attack Process
AU - Oliveira, Ítalo
AU - Wagner, Gerd
AU - Amaral, Glenda
AU - Sales, Tiago Prince
AU - Bullée, Jan-Willem
AU - Junger, Marianne
AU - Sarmah, Dipti K.
AU - Daneva, Maya
AU - Guizzardi, Giancarlo
N1 - Conference code: 26
PY - 2025/6/14
Y1 - 2025/6/14
N2 - Phishing attacks are common social engineering cyber attacks in which threat actors masquerade as reputable entities to mislead recipients into performing specific actions, such as revealing financial information, system login credentials, or installing malware. Grasping the phishing attack process is crucial to prevent and counteract this type of scam. Although useful, current conceptual models describing phishing attacks do not provide an unambiguous characterization to support human understanding, communication, and computational tasks. They are informal drawings, diagrams, data models, or schemata of application-focused RDF/OWL ontologies. Instead, we approach the problem by leveraging the Unified Foundational Ontology (UFO) and OntoUML modeling language to propose a Phishing Attack Process Ontology (PAPO), making ontological commitments explicit. We show that this ontological model supports risk identification, according to ISO 31000, and satisfies important quality requirements, including domain adequacy, transparency, logical and ontological coherence, generality, as well as the FAIR principles. By providing ontological foundations for the investigation and fight against phishing attacks, PAPO paves the way for rigorous representation of corresponding real-world scenarios and enhanced applications, such as systems interoperability, data modeling, knowledge-based systems, discrete event simulations, design of phishing detection systems, and evaluation of security mechanisms’ effectiveness.
AB - Phishing attacks are common social engineering cyber attacks in which threat actors masquerade as reputable entities to mislead recipients into performing specific actions, such as revealing financial information, system login credentials, or installing malware. Grasping the phishing attack process is crucial to prevent and counteract this type of scam. Although useful, current conceptual models describing phishing attacks do not provide an unambiguous characterization to support human understanding, communication, and computational tasks. They are informal drawings, diagrams, data models, or schemata of application-focused RDF/OWL ontologies. Instead, we approach the problem by leveraging the Unified Foundational Ontology (UFO) and OntoUML modeling language to propose a Phishing Attack Process Ontology (PAPO), making ontological commitments explicit. We show that this ontological model supports risk identification, according to ISO 31000, and satisfies important quality requirements, including domain adequacy, transparency, logical and ontological coherence, generality, as well as the FAIR principles. By providing ontological foundations for the investigation and fight against phishing attacks, PAPO paves the way for rigorous representation of corresponding real-world scenarios and enhanced applications, such as systems interoperability, data modeling, knowledge-based systems, discrete event simulations, design of phishing detection systems, and evaluation of security mechanisms’ effectiveness.
KW - 2025 OA procedure
KW - Pphishing attack process ontology
KW - Unified Foundational Ontology (UFO)
KW - OntoUML
KW - Phishing attack
UR - https://www.scopus.com/pages/publications/105009251719
U2 - 10.1007/978-3-031-95397-2_17
DO - 10.1007/978-3-031-95397-2_17
M3 - Conference contribution
SN - 978-3-031-95396-5
T3 - Lecture Notes in Business Information Processing
SP - 274
EP - 289
BT - Enterprise, Business-Process and Information Systems Modeling
A2 - Guizzardi, Renata
A2 - Pufahl, Luise
A2 - Sturm, Arnon
A2 - van der Aa, Han
PB - Springer Spektrum
CY - Cham, Switzerland
T2 - 26th International Conference, BPMDS 2025
Y2 - 16 June 2025 through 17 June 2025
ER -