The rise in cyber-attacks has intensified the challenges faced by digital forensics and security analysts, who must investigate complex incidents quickly while handling large volumes of heterogeneous evidence. Current tools lack standardisation, resulting in incomplete representations and poor interoperability. Ontologies address this by providing structured vocabularies that ensure consistency, enable integration, and support structured and AI-assisted reasoning. In this paper, we introduce OCAI, a novel ontology for cyber-attack attribution and investigation. Built on the widely adopted STIX 2.1 standard, OCAI extends it with investigation- and attribution-specific knowledge. We add new objects, relationships, and axioms that deliver richer, more consistent, and extensible knowledge representation useful for the investigation and attribution process. Through empirical evaluation on real-world cyber-attacks, we refined OCAI to address critical gaps and ensure broader representational coverage. Comparative analysis shows that OCAI provides a broader and more comprehensive representation of cyber-attack investigation and attribution than existing ontologies. Moreover, its integration into a reasoning-based attribution tool demonstrates improvements in knowledge representation and reasoning capabilities. Our novel ontology establishes a robust foundation for advancing cyber-attack investigations and attribution. • The paper introduces OCAI, the first ontology for cyber-attack investigation and attribution. • OCAI extends STIX 2.1 with investigation and attribution knowledge. • The paper enhances ontology expressiveness through real-world cyber-attack case studies. • Demonstrates applicability through integration into a reasoning-based attribution tool.
Gill et al. (Fri,) studied this question.