A Dynamic Fusion Approach for Security Situation Assessment

نویسندگان

  • Ambareen Siraj
  • Rayford B. Vaughn
چکیده

The need for higher-level reasoning capabilities beyond low-level sensor abilities has prompted researchers to use different types of sensor fusion techniques for better situational awareness in the intrusion detection environment. These techniques primarily vary in terms of their mission objectives. Some prioritize alerts for alert reduction, some cluster alerts to identify common attack patterns, and some correlate alerts to identify multistaged attacks. Each of these tasks has its own merits. Unlike previous efforts in this area, we have combined the primary tasks of sensor alert fusion, i.e., alert prioritization, alert clustering and alert correlation into a single framework such that individual results are used to quantify a confidence score as an overall assessment for global diagnosis of a systems’ security situation. In this paper, we particularly address the problem of fusing results of alert clustering and alert correlation for the determination of systems’ overall security health. We use a possibilistic approach in intelligent fusion of sensor alerts in order to accommodate the impreciseness and vagueness in knowledge-based reasoning. Experiments show that fusing higher level analysis results provides further insight into overall security situation of protected resources in the network.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Designing a Home Security System using Sensor Data Fusion with DST and DSMT Methods

Today due to the importance and necessity of implementing security systems in homes and other buildings, systems with higher certainty, lower cost and with sensor fusion methods are more attractive, as an applicable and high performance methods for the researchers. In this paper, the application of Dempster-Shafer evidential theory and also the newer, more general one Dezert-Smarandache theory ...

متن کامل

INFERD and Entropy for Situational Awareness

INFERD was created in the context of cyber security [25] as a decision aid tool to improve the analyst understanding of the situation and ultimately expedite their processing. To cope with the volumes and data rates of current sensed environments such as cyber security and others, decision aid tools must provide their assessment of the situation in a very time efficient manner. In most cases, t...

متن کامل

An Approach to Integrated Cognitive Fusion

– We describe the integration of two technologies to achieve cognitive fusion--the dynamic analysis of data combined from multiple sources in order to recognize complex dynamic situation patterns, construct models or hypotheses of unfolding situations, and take action in response to situations. The two technologies are temporal event correlation and case-based reasoning. We describe both techno...

متن کامل

A improved Network Security Situation Awareness Model

Fangwei Li Chongqing Key Lab of Mobile Communications Technology, Chongqing University of Posts and Telecommunications, Chongqing, China [email protected] Xinyue Zhang Chongqing Key Lab of Mobile Communications Technology, Chongqing University of Posts and Telecommunications, Chongqing, China [email protected] Jiang Zhu Chongqing Key Lab of Mobile Communications Technology, Chongqing Unive...

متن کامل

Fuzzy Logic in Decision Fusion for Situation Assessment

We present results of situation assessment that: i) uses type 1 fuzzy logic (T1FL) for decision making/fusion in some aviation scenarios, ii) uses modified situation assessment (pilot’s mental-) models, and iii) can have noisy inputs to the situation assessment models. The results indicate that some existing fuzzy logic implication functions in decision making/fusion work very well. This beacon...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007