An ontology-based intrusion alerts correlation system

被引:24
|
作者
Li, Wan [1 ]
Tian, Shengfeng [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing 100044, Peoples R China
关键词
Alert correlation; Intrusion detection; Ontology; System integration and implementation; RULES;
D O I
10.1016/j.eswa.2010.03.068
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Alert correlation techniques effectively improve the quality of alerts reported by intrusion detection systems, and are sufficient to support rapid identification of ongoing attacks or predict an intruder's next likely goal. In our previous work, an alert correlation approach based on our XSWRL ontology has been proposed. This paper focuses on how to develop the intrusion alerts correlation system according to our alert correlation approach. At first, the multi-agent system architecture consisting of agents and sensors is shown. The sensors collect security relevant information, and the agents process the information. Then we present each modules of the system in detail. The State Sensor collects information about security state and the Local State Agent and Center State Agent preprocess the security state information and convert it to ontology. The Attack Sensor collects information about attack and the Local Alert Agent and Center Alert Agent preprocess the alert information and convert it to ontology. The Attack Correlator correlates the attacks and outputs the attack sessions. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:7138 / 7146
页数:9
相关论文
共 50 条
  • [41] An Ontology-Based Representation of Vaulted System for HBIM
    Previtali, Mattia
    Brumana, Raffaella
    Stanga, Chiara
    Banfi, Fabrizio
    [J]. APPLIED SCIENCES-BASEL, 2020, 10 (04):
  • [42] An Ontology-Based Spatial Clustering Selection System
    Gu, Wei
    Wang, Xin
    Ziebelin, Danielle
    [J]. ADVANCES IN ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2009, 5549 : 215 - +
  • [43] A Proposal of an Ontology-based System for Distributed Teams
    Rocha, Rodrigo G. C.
    Azevedo, Ryan
    Meira, Silvio
    [J]. 2014 40TH EUROMICRO CONFERENCE SERIES ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2014), 2014, : 398 - 401
  • [44] Ontology-Based System for Educational Program Counseling
    Majid, Mamoona
    Hayat, Muhammad Faisal
    Khan, Farrukh Zeeshan
    Ahmad, Muneer
    Jhanjhi, N. Z.
    Bhuiyan, Mohammad Arif Sobhan
    Masud, Mehedi
    AlZain, Mohammed A.
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2021, 30 (01): : 373 - 386
  • [45] An ontology-based cancer pain management system
    Ghosh, K
    [J]. METMBS'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON MATHEMATICS AND ENGINEERING TECHNIQUES IN MEDICINE AND BIOLOGICAL SCIENCES, 2003, : 181 - 185
  • [46] An ontology-based approach for federated identity system
    Wu, Min
    [J]. DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2006, 13 : 151 - 155
  • [47] A Collaborative Ontology-Based User Profiles System
    Duong, Trong Hai
    Uddin, Mohammed Nazim
    Li, Delong
    Jo, Geun Sik
    [J]. COMPUTATIONAL COLLECTIVE INTELLIGENCE: SEMANTIC WEB, SOCIAL NETWORKS AND MULTIAGENT SYSTEMS, 2009, 5796 : 540 - 552
  • [48] A system for ontology-based annotation of biomedical data
    Jonquet, Clement
    Musen, Mark A.
    Shah, Nigam
    [J]. DATA INTEGRATION IN THE LIFE SCIENCES, PROCEEDINGS, 2008, 5109 : 144 - 152
  • [49] Vulcain - An ontology-based information extraction system
    Todirascu, A
    Romary, L
    Bekhouche, D
    [J]. NATURAL LANGUAGE PROCESSING AND INFORMATION SYSTEMS, 2002, 2553 : 64 - 75
  • [50] An Ontology-Based System for Cancer Registry Data
    Casey, Shinead
    Doody, Pat
    Shields, Andrew
    [J]. 2022 33RD IRISH SIGNALS AND SYSTEMS CONFERENCE (ISSC), 2022,