An ontology-based intrusion alerts correlation system

被引:24
|
作者
Li, Wan [1 ]
Tian, Shengfeng [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing 100044, Peoples R China
关键词
Alert correlation; Intrusion detection; Ontology; System integration and implementation; RULES;
D O I
10.1016/j.eswa.2010.03.068
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Alert correlation techniques effectively improve the quality of alerts reported by intrusion detection systems, and are sufficient to support rapid identification of ongoing attacks or predict an intruder's next likely goal. In our previous work, an alert correlation approach based on our XSWRL ontology has been proposed. This paper focuses on how to develop the intrusion alerts correlation system according to our alert correlation approach. At first, the multi-agent system architecture consisting of agents and sensors is shown. The sensors collect security relevant information, and the agents process the information. Then we present each modules of the system in detail. The State Sensor collects information about security state and the Local State Agent and Center State Agent preprocess the security state information and convert it to ontology. The Attack Sensor collects information about attack and the Local Alert Agent and Center Alert Agent preprocess the alert information and convert it to ontology. The Attack Correlator correlates the attacks and outputs the attack sessions. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:7138 / 7146
页数:9
相关论文
共 50 条
  • [1] Preprocessor of Intrusion Alerts Correlation Based on Ontology
    Li, Wan
    Tian, Shengfeng
    [J]. 2009 WRI INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND MOBILE COMPUTING: CMC 2009, VOL 3, 2009, : 460 - +
  • [2] An ontology-based modelling and reasoning for alerts correlation
    Kenaza, Tayeb
    [J]. INTERNATIONAL JOURNAL OF DATA MINING MODELLING AND MANAGEMENT, 2021, 13 (1-2) : 65 - 80
  • [3] Intrusion Alerts Correlation Model Based on XSWRL Ontology
    Li, Wan
    Zhu, Yan
    Tian, Shengfeng
    [J]. 2008 INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY APPLICATION, VOL I, PROCEEDINGS, 2008, : 894 - 898
  • [4] Ontology-based Distributed Intrusion Detection System
    Abdoli, F.
    Kahani, M.
    [J]. 2009 14TH INTERNATIONAL COMPUTER CONFERENCE, 2009, : 65 - +
  • [5] Ontology-based correlation engines
    Stojanovic, L
    Abecker, A
    Stojanovic, N
    Studer, R
    [J]. INTERNATIONAL CONFERENCE ON AUTONOMIC COMPUTING, PROCEEDINGS, 2004, : 304 - 305
  • [6] An Ontology-based Intrusion Detection for RFID Systems
    Esposito, M.
    Della Vecchia, G.
    [J]. TECHNOLOGICAL DEVELOPMENTS IN NETWORKING, EDUCATION AND AUTOMATION, 2010, : 467 - 472
  • [7] From Intrusion Detection to Intrusion Detection and Diagnosis: An Ontology-Based Approach
    Coppolino, Luigi
    D'Antonio, Salvatore
    Elia, Ivano Alessandro
    Romano, Luigi
    [J]. SOFTWARE TECHNOLOGIES FOR EMBEDDED AND UBIQUITOUS SYSTEMS, PROCEEDINGS, 2009, 5860 : 192 - 202
  • [8] An ontology-based network intrusion detection system: A user-oriented approach
    Hung, Shao-Shin
    Liu, Damon Shing-Min
    [J]. INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2006, 3975 : 722 - 723
  • [9] Alerts correlation system to enhance the performance of the network-based intrusion detection system
    Lee, DH
    Seo, JT
    Ryou, JC
    [J]. GRID AND COOPERATIVE COMPUTING GCC 2004, PROCEEDINGS, 2004, 3251 : 333 - 340
  • [10] An Ontology-based Multiagent Architecture for Outbound Intrusion Detection
    Mandujano, Salvador
    Galvan, Arturo
    Nolazco, Juan A.
    [J]. 3RD ACS/IEEE INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS, 2005, 2005,