A Dynamic Fusion Approach for Security Situation Assessment
نویسندگان
چکیده
The need for higher-level reasoning capabilities beyond low-level sensor abilities has prompted researchers to use different types of sensor fusion techniques for better situational awareness in the intrusion detection environment. These techniques primarily vary in terms of their mission objectives. Some prioritize alerts for alert reduction, some cluster alerts to identify common attack patterns, and some correlate alerts to identify multistaged attacks. Each of these tasks has its own merits. Unlike previous efforts in this area, we have combined the primary tasks of sensor alert fusion, i.e., alert prioritization, alert clustering and alert correlation into a single framework such that individual results are used to quantify a confidence score as an overall assessment for global diagnosis of a systems’ security situation. In this paper, we particularly address the problem of fusing results of alert clustering and alert correlation for the determination of systems’ overall security health. We use a possibilistic approach in intelligent fusion of sensor alerts in order to accommodate the impreciseness and vagueness in knowledge-based reasoning. Experiments show that fusing higher level analysis results provides further insight into overall security situation of protected resources in the network.
منابع مشابه
Designing a Home Security System using Sensor Data Fusion with DST and DSMT Methods
Today due to the importance and necessity of implementing security systems in homes and other buildings, systems with higher certainty, lower cost and with sensor fusion methods are more attractive, as an applicable and high performance methods for the researchers. In this paper, the application of Dempster-Shafer evidential theory and also the newer, more general one Dezert-Smarandache theory ...
متن کاملINFERD and Entropy for Situational Awareness
INFERD was created in the context of cyber security [25] as a decision aid tool to improve the analyst understanding of the situation and ultimately expedite their processing. To cope with the volumes and data rates of current sensed environments such as cyber security and others, decision aid tools must provide their assessment of the situation in a very time efficient manner. In most cases, t...
متن کاملAn Approach to Integrated Cognitive Fusion
We describe the integration of two technologies to achieve cognitive fusion--the dynamic analysis of data combined from multiple sources in order to recognize complex dynamic situation patterns, construct models or hypotheses of unfolding situations, and take action in response to situations. The two technologies are temporal event correlation and case-based reasoning. We describe both techno...
متن کاملA improved Network Security Situation Awareness Model
Fangwei Li Chongqing Key Lab of Mobile Communications Technology, Chongqing University of Posts and Telecommunications, Chongqing, China [email protected] Xinyue Zhang Chongqing Key Lab of Mobile Communications Technology, Chongqing University of Posts and Telecommunications, Chongqing, China [email protected] Jiang Zhu Chongqing Key Lab of Mobile Communications Technology, Chongqing Unive...
متن کاملFuzzy Logic in Decision Fusion for Situation Assessment
We present results of situation assessment that: i) uses type 1 fuzzy logic (T1FL) for decision making/fusion in some aviation scenarios, ii) uses modified situation assessment (pilot’s mental-) models, and iii) can have noisy inputs to the situation assessment models. The results indicate that some existing fuzzy logic implication functions in decision making/fusion work very well. This beacon...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007