An ontology-based intrusion alerts correlation system

被引:24
|
作者
Li, Wan [1 ]
Tian, Shengfeng [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing 100044, Peoples R China
关键词
Alert correlation; Intrusion detection; Ontology; System integration and implementation; RULES;
D O I
10.1016/j.eswa.2010.03.068
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Alert correlation techniques effectively improve the quality of alerts reported by intrusion detection systems, and are sufficient to support rapid identification of ongoing attacks or predict an intruder's next likely goal. In our previous work, an alert correlation approach based on our XSWRL ontology has been proposed. This paper focuses on how to develop the intrusion alerts correlation system according to our alert correlation approach. At first, the multi-agent system architecture consisting of agents and sensors is shown. The sensors collect security relevant information, and the agents process the information. Then we present each modules of the system in detail. The State Sensor collects information about security state and the Local State Agent and Center State Agent preprocess the security state information and convert it to ontology. The Attack Sensor collects information about attack and the Local Alert Agent and Center Alert Agent preprocess the alert information and convert it to ontology. The Attack Correlator correlates the attacks and outputs the attack sessions. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:7138 / 7146
页数:9
相关论文
共 50 条
  • [21] Ontology-Based Music Recommender System
    Angel Rodriguez-Garcia, Miguel
    Omar Colombo-Mendoza, Luis
    Valencia-Garcia, Rafael
    Lopez-Lorca, Antonio A.
    Beydoun, Ghassan
    DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE, 12TH INTERNATIONAL CONFERENCE, 2015, 373 : 39 - 46
  • [22] An Ontology-Based Collaborative Design System
    Su, Tieming
    Qiu, Xinpeng
    Yu, Yunlong
    COOPERATIVE DESIGN, VISUALIZATION, AND ENGINEERING, PROCEEDINGS, 2009, 5738 : 69 - 76
  • [23] Ontology-Based Pattern for System Engineering
    Ernadote, Dominique
    2017 ACM/IEEE 20TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS (MODELS 2017), 2017, : 248 - 258
  • [24] An ontology-based information retrieval system
    Varga, P
    Mészáros, T
    Dezsényi, C
    Dobrowiecki, TP
    DEVELOPMENTS IN APPLIED ARTIFICIAL INTELLIGENCE, 2003, 2718 : 359 - 368
  • [25] Ontology-based Robust Production System
    Yip, Frederick
    Wong, Alfred K. Y.
    Parameswaran, Nandan
    Ray, Pradeep
    2009 IEEE THIRD INTERNATIONAL CONFERENCE ON SEMANTIC COMPUTING (ICSC 2009), 2009, : 428 - 433
  • [26] Ontology-based learning support system
    Graudina, Vita
    DATABASES AND INFORMATION SYSTEMS: COMMUNICATIONS, MATERIALS OF DOCTORAL CONSORTIUM, 2006, : 316 - 317
  • [27] An ontology-based publish/subscribe system
    Wang, JL
    Jin, BH
    Li, J
    MIDDLEWARE 2004, PROCEEDINGS, 2004, 3231 : 232 - 253
  • [28] Ontology-based Semantic Retrieval System
    Zhang, Xiaohuan
    Li, Wenjie
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 10944 - +
  • [29] ONTOLOGY-BASED EDUCATIONAL INFORMATION SYSTEM
    Tarcsi, Adam
    Nyitrai, Erika
    Varga, Balazs
    PROCEEDINGS OF THE IADIS INTERNATIONAL CONFERENCE E-LEARNING 2012, 2012, : 193 - 202
  • [30] Ontology-based system for Enterprise 2.0
    Mangione, Giuseppina Rita
    Miranda, Sergio
    Paolozzi, Stefano
    Pierri, Anna
    Ritrovato, Pierluigi
    Salerno, Saverio
    2009 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, 2009, : 890 - +