Description logics for an autonomic IDS event analysis system

نویسندگان

  • Wei Yan
  • Edwin S. H. Hou
  • Nirwan Ansari
چکیده

Internet has grown by several orders of magnitude in recent years, and this growth has escalated the importance of computer security. Intrusion Detection System (IDS) is used to protect computer networks. However, the overwhelming flow of log data generated by IDS hamper security administrators from uncovering the hidden attack scenarios. Therefore, the autonomic IDS event analysis system is essential to make the IDS console smarter and more efficient. In this paper, we propose an IDS autonomic event analysis system represented by description logics, which allows inferring the attack scenarios and enabling the attack knowledge semantic queries. The modified case grammar PCTCG is used to convert raw alerts into frame-structured alert streams, and the alert semantic network 2-AASN is used to generate the attack scenarios, which can then inform the security administrator. Afterwards, based on the alert contexts, attack scenario instances are extracted, and attack semantic query results on attack scenario instances using spreading activation technique are forwarded to the security administrator. 2006 Published by Elsevier B.V.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Using Correlation Detection for IMA-IDS Architecture

This paper presents a new syntactic and semantic representation for network events. Our goal is to offer to IMA-IDS (Intelligent and Mobile Agent Intrusion Detection System), an efficient correlation engine. IMAIDS is a global architecture for using intelligent and mobile agent for intrusion detection system. As described widely in [1] this architecture aims at taking advantages of agent mobili...

متن کامل

An Autonomic Intrusion Detection Model with Multi-Attribute Auction Mechanism

We present an innovative intrusion detection model based on autonomic computing to extend the passive detection mechanism in a traditional intrusion detection system (IDS). Centered on an autonomic manager, this model introduces a multi-attribute auction mechanism in the agent coordination layer to perceive environmental changes, manage and allocate resources, and achieve an active response to ...

متن کامل

Evaluation of an Intrusion Detection System for Routing Attacks in Wireless Self-organised Networks

Wireless Sensor Networks (WSNs) arebecoming increasingly popular, and very useful in militaryapplications and environmental monitoring. However,security is a major challenge for WSNs because they areusually setup in unprotected environments. Our goal in thisstudy is to simulate an Intrusion Detection System (IDS)that monitors the WSN and report intrusions accurately andeffectively. We have thus...

متن کامل

Abnormal Event Detection for Network Flooding Attacks

Due to the high demand for network service availability and reliability, the IDS (Intrusion Detecting System) has become an essential element for IP networks. Currently, most IDSs use a pattern-matching mechanism to detect network flooding attacks. However, while running, such a mechanism needs to take into considerable the computing time/resource of an IDS or an IDS-embedded router. This can e...

متن کامل

Semantic Indexing Based on Description Logics

A method for constructing and maintaining a `semantic index' using a system based on description logics is described. A persistent index into a large number of objects is built by classifying the objects with respect to a set of indexing concepts and storing the resulting relation between object-ids and most speciic indexing concepts on a le. These les can be incre-mentally updated. The index c...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computer Communications

دوره 29  شماره 

صفحات  -

تاریخ انتشار 2006