The article discusses the task of formalizing knowledge about software weaknesses based on the international Common Weakness Enumeration (CWE) list with a focus on the representation of Architectural Concepts. The relevance of the research is due to the growing number of cyber attacks and the need to take into account security threats not only at the operational stage, but also at the stages of designing and developing software systems. The purpose of the work is to study the system of software weaknesses based on CWE and to develop an ontological knowledge base focused on the needs of software architects. The research uses methods of analysis and synthesis, classification, logical and system analysis, as well as ontological modeling based on OWL, RDF and Protégé environment. As a result, an ontology has been developed in which the central element is the CWEEntries class, associated with the CVEEntries and CAPECEntries classes, which allows us to formalize the relationship between weaknesses, vulnerabilities and attack patterns. The conducted testing using SPARQL queries showed that the developed knowledge base supports semantic search, analysis of relationships between entities and solving applied problems related to the early detection of architectural risks. The scientific novelty of the work lies in the presentation of the architectural representation of CWE as a machine-readable ontological model of knowledge. The practical significance lies in the possibility of using the proposed knowledge base by architects, developers, researchers and teachers in secure-by-design tasks.
SARTABANOVA ZH.E.
PhD, senior lecturer, Heriot Watt university, Aktobe Campus, Aktobe, Kazakhstan.
E-mail: Z.Sartabanova@hw.ac.uk, https://orcid.org/0000-0003-4942-5117
DIMITROV V.T.
PhD, professor, faculty of mathematics and informatics, Sofia university St. Kliment Ohridski, Sofia, Bulgary
E-mail: cht@fmi.uni-sofia.bg, https://orcid.org/0000-0002-7441-253X
URDABAYEVA G.ZH.
Master, lecturer, K.Zhubanov Aktobe regional university, Aktobe, Kazakhstan.
E-mail: g.urdabaeva@zhubanov.edu.kz, https://orcid.org/0000-0002-2723-7783
ARULMURUGAN R.
PhD, associate professor, Department of information technology university, Mattu University, Mattu, Ethiopia
E-mail: A.Ramu@hw.ac.uk, https://orcid.org/0000-0003-1030-9565
- MITRE. About CWE [Electronic resource]. – 2024. – URL: https://cwe.mitre.org/ (date of request: 26.03.2026).
- MITRE. CWE-1008: Architectural Concepts. CWE View 1008 [Electronic resource]. – 2026. – URL: https://cwe.mitre.org/data/definitions/1008.html (date of request: 26.03.2026).
- Kanakogi K., Washizaki H., Fukazawa Y., Ogata S., Okubo T., Kato T., Kanuka H., Hazeyama A., Yoshioka N. Tracing CVE Vulnerability Information to CAPEC Attack Patterns Using Natural Language Processing Techniques // Information. – 2021. – Vol. 12, No. 8. – Art. 298. – DOI: 10.3390/info12080298.
- Özdemir Sönmez F., Hankin C., Malacaria P. Attack Dynamics: An Automatic Attack Graph Generation Framework Based on System Topology, CAPEC, CWE, and CVE Databases // Computers & Security. – 2022. – Vol. 123. – Art. 102938. – DOI: 10.1016/j.cose.2022.102938.
- Santos J. C. S., Tarrit K., Mirakhorli M. A Catalog of Security Architecture Weaknesses // 2017 IEEE International Conference on Software Architecture Workshops (ICSAW). – 2017. – P. 220–223. – DOI: 10.1109/ICSAW.2017.25.
- Santos J. C. S., Peruma A., Mirakhorli M., Galster M., Veloz Vidal J., Sejfia A. Understanding Software Vulnerabilities Related to Architectural Security Tactics: An Empirical Investigation of Chromium, PHP and Thunderbird // 2017 IEEE International Conference on Software Architecture (ICSA). – 2017. – P. 69–78. – DOI: 10.1109/ICSA.2017.39.
- Musen M. A. The Protégé Project: A Look Back and a Look Forward // AI Matters. – 2015. – Vol. 1, No. 4. – P. 4–12. – DOI: 10.1145/2757001.2757003.
- W3C. OWL 2 Web Ontology Language Document Overview [Electronic resource]: W3C Recommendation. – 2012. – URL: https://www.w3.org/TR/owl2-overview/ (date of request: 26.03.2026).
- W3C. RDF 1.1 Concepts and Abstract Syntax [Electronic resource]: W3C Recommendation. – 2014. – URL: https://www.w3.org/TR/rdf11-concepts/ (date of request: 26.03.2026).
- Sartabanova Zh., Dimitrov V. Modelling of CWEs on the CWE-287 Example // CEUR Workshop Proceedings. – 2019. – Vol. 2464.
- Sartabanova Zh., Dimitrov V. T., Sarsimbaeva S. M. Applying the Knowledge Base of CWE Weaknesses in Software Design // Journal of Mathematics, Mechanics and Computer Science. – Al-Farabi Kazakh National University. – 2020. Vol. 108, No. 4. – P. 72–80. – DOI: 10.26577/JMMCS.2020.v108.i4.06
