A Semantic approach for Automating Knowledge in Policies of Cyber Insurance Services

Author/Creator ORCID

Date

2020-01-01

Department

Information Systems

Program

Information Systems

Citation of Original Publication

Rights

Access limited to the UMBC community. Item may possibly be obtained via Interlibrary Loan thorugh a local library, pending author/copyright holder's permission.
This item may be protected under Title 17 of the U.S. Copyright Law. It is made available by UMBC for non-commercial research and education. For permission to publish or reproduce, please see http://aok.lib.umbc.edu/specoll/repro.php or contact Special Collections at speccoll(at)umbc.edu

Subjects

Abstract

With the rapid enhancements in technology and adoption of web services, there has been a huge increase in number of cyber threats. It has become a necessity to get a financial cover to mitigate the expenses in the security incident. Organizations are willing to get enough coverage which they can use to safeguard the third-party services they use. The cyber insurance policies include the coverages and exclusions using legal jargon which can be difficult to understand. To parse these policy documents and to extract the legal key terms manually is a very time-consuming process. We have developed a framework which automatically extracts the coverage and exclusion key terms and rules embedded in the policy. Our system also represents the extracted key terms in a form which user can query upon. We built our framework using semantic web technologies and deontic logic. To validate our approach, we used industry standards proposed by the Federal Trade Commission document (FTC) and applied it against publicly available policies of seven insurance providers. We have built web user interface platform where a user can find the best matching cyber insurance policy based on coverage criteria provided at runtime.