Knowledge-Augmented Security Risk Identification for OT Container Deployments

Yannick Landeck , Tomas Bueno Momčilović , Dian Balta , Martin Wimmer und Christian Knierim

24th International Semantic Web Conference: Companion Volume (ISWC-C 2025),

November 2025 · Nara, Japan

Zusammenfassung

Container deployments in operational technology (OT) environments pose unique security challenges, especially when privileged configurations are used. Traditional risk identification methods often fall short in addressing the complexity, dynamic nature, and interdisciplinary collaboration required in these settings. We propose a knowledge augmentation approach that combines semantic modelling, automated reasoning, and tool support to enhance security risk identification. Our approach is demonstrated through an industrial case study, highlighting its practical application. We also examine how large language models (LLMs) can support the instantiation and integration of the approach, improving usability and scalability.

Stichworte: peng, Security Risk Assessment, Container Security, Knowledge Augmentation, Operational Technology

Url: https://ceur-ws.org/Vol-4085/paper3.pdf