A Learning Framework for Transitioning Network Intrusion Alerts Management System to Ontology

被引:0
作者
Fu, Chunlei [1 ]
Duan, Qichang [2 ]
Fu, Li [3 ]
Xiang, Hong [3 ]
Xiong, Zhongyang [1 ]
Hu, Haibo [3 ]
机构
[1] Chongqing Univ, Informat & Network Management Ctr, Chongqing, Peoples R China
[2] Chongqing Univ, Sch Automat, Chongqing, Peoples R China
[3] Chongqing Univ, Sch Software Engn, Chongqing, Peoples R China
来源
JOURNAL OF RESEARCH AND PRACTICE IN INFORMATION TECHNOLOGY | 2011年 / 43卷 / 03期
关键词
Intrusion Detection; Intrusion Alerts Correlation; Ontology learning; RELATIONAL DATABASES; MODEL;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection is not new in the area of information security. It is crucial for the intrusion alerts management system to correlate the collected intrusion alerts to reflect the causal relationships between the attack steps and construct the attack scenarios. Most of these systems, however, have been built on the relational database logging the intrusion alerts. The relational database has been proven to be a very useful model and applied in the wide area. But their persisting limitation lies in the flat structure which is not capable of representing the complex relations. An ontology is an explicit specification of a conceptualization using an agreed vocabulary. In this paper, ontology is put into use and a learning framework is presented which depicts how the intrusion alerts ontology can be learned and further enriched exploiting both the database schema and the stored data. Moreover, we introduce the vulnerabilities database to refine the ontology hierarchy and the restriction of classes and apply the ontology design pattern to represent the sequence of a series of events. The whole transitioning process is implemented in OBNAMS, an intrusion alerts management system constructed on the learned ontology automating the consisted steps.
引用
收藏
页码:247 / 265
页数:19
相关论文
共 26 条
[1]   Ontology-based Distributed Intrusion Detection System [J].
Abdoli, F. ;
Kahani, M. .
2009 14TH INTERNATIONAL COMPUTER CONFERENCE, 2009, :65-+
[2]  
[Anonymous], 2000, DARPA INTR DET SCEN
[3]  
[Anonymous], 2003, DESCRIPTION LOGIC HD
[4]  
[Anonymous], 2001, INT WORKSH REC ADV I
[5]  
ASTROVA I., 2004, LNCS, V3053, P37
[6]  
Cerbah F, 2010, STUD COMPUT INTELL, V292, P271
[7]  
Cheng YC, 2007, GRC: 2007 IEEE INTERNATIONAL CONFERENCE ON GRANULAR COMPUTING, PROCEEDINGS, P368
[8]   REVERSE ENGINEERING OF RELATIONAL DATABASES - EXTRACTION OF AN EER MODEL FROM A RELATIONAL DATABASE [J].
CHIANG, RHL ;
BARRON, TM ;
STOREY, VC .
DATA & KNOWLEDGE ENGINEERING, 1994, 12 (02) :107-142
[9]  
Cuppens F, 2000, LECT NOTES COMPUT SC, V1907, P197
[10]  
Cuppens F, 2001, 17 ANN COMP SEC APPL