TIDO: The Threat Intelligence Decision Ontology

Open Access
Authors
Publication date 2025
Book title K-CAP '25
Book subtitle Proceedings of the 13th Knowledge Capture Conference 2025 : Dayton, Ohio, USA
ISBN (electronic)
  • 9798400718670
Event 13th International Conference on Knowledge Capture, K-CAP 2025
Pages (from-to) 82-89
Number of pages 8
Publisher New York, New York: Association for Computing Machinery
Organisations
  • Faculty of Science (FNWI) - Informatics Institute (IVI)
Abstract

National intelligence agencies have the complex task of investigating threats to the national security within strict legal and policy frameworks. Reconstructing the context of investigative decisions for post-analysis and compliance checks is prone to error and labour-intensive. To address this, we propose to capture decision-making processes and their rationale directly using an OWL-based ontology. This approach overcomes the limitations of traditional data management and existing decision ontologies in handling the intricate data dependencies within threat intelligence (TI) decision-making. The result is the Threat Intelligence Decision Ontology (TIDO), which structures analysts' decision-making while incrementally capturing a decision trace for post-analysis as investigations unfold. The ontology was developed under the complex constraints of safeguarding threat intelligence practices and case information, and validated through competency questions from intelligence experts from the Dutch Defence Intelligence and Security Service (DISS). TIDO offers a novel solution for capturing and understanding decision processes within the sensitive domain of threat intelligence, and evidence-based decision-making in general.

Document type Conference contribution
Language English
Published at https://doi.org/10.1145/3731443.3771351
Other links https://www.scopus.com/pages/publications/105024937312
Downloads
3731443.3771351 (Final published version)
Permalink to this page
Back