An ontology-based modelling and reasoning for alerts correlation

被引:4
|
作者
Kenaza, Tayeb [1 ]
机构
[1] Ecole Mil Polytech, BP 17 BEB, Algiers 16111, Algeria
关键词
information security; intrusion detection; security information and event management system; SIEM; alert correlation; rules-based reasoning; ontology; ontology web language; OWL; Semantic Web Rule Language; SWRL; INTRUSION DETECTION;
D O I
10.1504/IJDMMM.2021.112913
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
SIEM is a modern and powerful security tool thanks to several functions that it provides to take benefit of collected data, such as normalisation and aggregation. The main important function is events correlation, when security operators can get a precise and quick picture about threats and attacks in real-time. The quality of that picture depends on the efficiency of the adopted reasoning approach to putting together pieces of information provided by several analysers. In this paper, we propose a semantic approach based on description logics (DLs) which is a powerful tool for knowledge representation and reasoning. Indeed, ontology provides a comprehensive environment to represent information for intrusion detection and allows easy maintaining of information or adding new ones. We implemented a rule-based engine for alert correlation based on the proposed ontology and two attack scenarios are carried out to show the usefulness of our approach.
引用
收藏
页码:65 / 80
页数:16
相关论文
共 50 条
  • [1] An ontology-based intrusion alerts correlation system
    Li, Wan
    Tian, Shengfeng
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2010, 37 (10) : 7138 - 7146
  • [2] An Ontology-Based Approach for the Semantic Modelling and Reasoning on Trajectories
    Baglioni, Miriam
    Macedo, Jose
    Renso, Chiara
    Wachowicz, Monica
    [J]. ADVANCES IN CONCEPTUAL MODELING - CHALLENGES AND OPPORTUNITIES, 2008, 5232 : 344 - +
  • [3] An ontology-based modelling and reasoning framework for assembly sequence planning
    [J]. Zhu, Yixin (chunic@buaa.edu.cn), 1600, Springer London (94): : 9 - 12
  • [4] An ontology-based modelling and reasoning framework for assembly sequence planning
    Lihong Qiao
    Yifan Qie
    Zuowei Zhu
    Yixin Zhu
    Uzair Khaleeq uz Zaman
    Nabil Anwer
    [J]. The International Journal of Advanced Manufacturing Technology, 2018, 94 : 4187 - 4197
  • [5] An ontology-based modelling and reasoning framework for assembly sequence planning
    Qiao, Lihong
    Qie, Yifan
    Zhu, Zuowei
    Zhu, Yixin
    Zaman, Uzair Khaleeq Uz
    Anwer, Nabil
    [J]. INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2018, 94 (9-12): : 4187 - 4197
  • [6] An ontology-based modelling and reasoning framework for assembly process selection
    Das, Shantanu Kumar
    Swain, Abinash Kumar
    [J]. INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2022, 120 (7-8): : 4863 - 4887
  • [7] An ontology-based modelling and reasoning framework for assembly process selection
    Shantanu Kumar Das
    Abinash Kumar Swain
    [J]. The International Journal of Advanced Manufacturing Technology, 2022, 120 : 4863 - 4887
  • [8] AN ONTOLOGY-BASED REASONING FRAMEWORK
    Pei, Wanyu
    Xiong, Shuyan
    Habert, Guillaume
    Stouffs, Rudi
    [J]. PROCEEDINGS OF THE 29TH INTERNATIONAL CONFERENCE OF THE ASSOCIATION FOR COMPUTER-AIDED ARCHITECTURAL DESIGN RESEARCH IN ASIA, CAADRIA 2024, VOL 2, 2024, : 335 - 344
  • [9] Ontology-based Modelling and Reasoning for Forest Fire Emergencies in Resilient Societies
    Masa, Panagiota
    Meditskos, Georgios
    Kintzios, Spyridon
    Vrochidis, Stefanos
    Kompatsiaris, Ioannis
    [J]. PROCEEDINGS OF THE 12TH HELLENIC CONFERENCE ON ARTIFICIAL INTELLIGENCE, SETN 2022, 2022,
  • [10] Research on Ontology-based Semantic Reasoning
    Song, Lan
    Lei, Lixia
    Wang, Hong
    Hua, Junhong
    [J]. ACHIEVEMENTS IN ENGINEERING MATERIALS, ENERGY, MANAGEMENT AND CONTROL BASED ON INFORMATION TECHNOLOGY, PTS 1 AND 2, 2011, 171-172 : 136 - +