Using DAML+OIL to classify intrusive behaviours

نویسندگان

  • Jeffrey Undercoffer
  • Anupam Joshi
  • Timothy W. Finin
  • John Pinkston
چکیده

We have produced an ontology specifying a model of computer attack. Our ontology is based upon an analysis of over 4000 classes of computer intrusions and their corresponding attack strategies and is categorised according to system component targeted, means of attack, consequence of attack and location of attacker. We argue that any taxonomic characteristics used to define a computer attack be limited in scope to those features that are observable and measurable at the target of the attack. We present our model as a target-centric ontology that is to be refined and expanded over time. We state the benefits of forgoing dependence upon taxonomies in favour of ontologies for the classification of computer attacks and intrusions. We have specified our ontology using the DARPA Agent Markup Language+Ontology Inference Layer and have prototyped it using DAMLJessKB. We present our model as a target-centric ontology and illustrate the benefits of utilising an ontology in lieu of a taxonomy, by presenting a use-case scenario of a distributed intrusion detection system.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Results of Taxonomic Evaluation of RDF(S) and DAML+OIL ontologies using RDF(S) and DAML+OIL Validation Tools and Ontology Platforms import services

Before using RDF(S) and DAML+OIL ontologies in Semantic Web applications, its content should be evaluated from a knowledge representation point of view. In recent years, some RDF(S) and DAML+OIL ‘checkers’, ‘validators’, and ‘parsers’ have been created and several ontology platforms are able to import RDF(S) and DAML+OIL ontologies. Two are the experiments presented in this paper. The first one...

متن کامل

DAML+OIL: A Reason-able Web Ontology Language

Ontologies are set to play a key role in the ”Semantic Web”, extending syntactic interoperability to semantic interoperability by providing a source of shared and precisely defined terms. DAML+OIL is an ontology language specifically designed for use on the web; it exploits existing web standards (XML and RDF), adding the familiar ontological primitives of object oriented and frame based system...

متن کامل

The Generation of DAML+OIL

daml+oil is a new description logic developed for use within the DAML project and as a submission to the upcoming W3C semantic web ontology working group. It is closely based on the oil, but also has strong influences from the existing W3C efforts as well as input from DAML researchers. daml+oil pushes very close to the undecidability barrier. Developing effective reasoners for daml+oil will st...

متن کامل

A use case for DAML+OIL: a knowledge base in a clinical domain

This paper describes how we have developed a knowledge base for a heuristic application in a clinical domain. Firstly, the knowledge base has been modelled using CommonKADS. Later, the knowledge base has been represented in the language DAML+OIL. We will illustrate in some depth how objects, classes and relationships of a medical domain (modelled following an object-oriented approach) can be sp...

متن کامل

ODEVAL: A Tool for Evaluating RDF(S), DAML+OIL and OWL Concept Taxonomies

Ontologies implemented in RDF(S), DAML+OIL, and OWL should be evaluated from the point of view of knowledge representation before using them in Semantic Web applications. Several language-dependent ontology validation tools and ontology platforms, such as OilEd with FaCT, can be used in order to evaluate RDF(S), DAML+OIL and OWL ontologies. This paper offers two main contributions. The first of...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Knowledge Eng. Review

دوره 18  شماره 

صفحات  -

تاریخ انتشار 2003