کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
485349 703325 2016 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Toward an Efficient Ontology-Based Event Correlation in SIEM
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر علوم کامپیوتر (عمومی)
پیش نمایش صفحه اول مقاله
Toward an Efficient Ontology-Based Event Correlation in SIEM
چکیده انگلیسی

Cooperative intrusion detection use several intrusion detection systems (IDS) and analyzers in order to build a reliable overview of the monitored system trough a central security information and event management system (SIEM). In such environment, the definition of a shared vocabulary describing the exchanged information between tools is prominent. Since these pieces of information are structured, we propose in this paper to use an ontological representation based on Description Logics (DLs) which is a powerful tool for knowledge representation. Moreover, DLs are able to ensure a decidable reasoning. An alert correlation prototype is presented using this ontology, and an illustrative attack scenario is carried out to show the usefulness of the proposed ontology.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Procedia Computer Science - Volume 83, 2016, Pages 139–146
نویسندگان
, ,