ONTIDS: A flexible context-aware and ontology-based alert correlation framework

نویسندگان

  • Alireza Sadighian
  • José M. Fernandez
  • Antoine Lemay
  • Saman T. Zargar
  • S. T. Zargar
چکیده

In order to reduce the numbers of non-relevant alerts and false positives typically generated by Intrusion Detection Systems (IDS) in real-world situations, several alert correlation approaches that integrate and jointly analyse the alert streams of different alert sensors have been proposed. Inspired by the mental process of contextualisation used by security analysts to weed out less relevant alerts, some of these approaches have tried to incorporate into the correlation process contextual information such as type of systems, applications, users, and networks. However, they tend to be limited in flexibility, as they only perform correlation based on narrowly defined definitions of context. In order to provide a method to automate the analysis of the various information resources available to the security analyst, while preserving maximum flexibility and power of abstraction in the definition and use of such concepts, we propose the ONTIDS ontology-based correlation alert framework. ONTIDS uses ontologies to represent and store information on alerts, context and vulnerability information, and attack scenarios, and uses simple ontology logic rules written in Semantic Query-Enhance Web Rule Language (SQWRL) to correlate and filter out non-relevant alerts. We illustrate the potential usefulness and flexibility of our framework by describing a reference implementation that we use on two separate analysis case study scenarios, inspired from the DARPA 2000 and UNB ISCX IDS evaluation datasets.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards a Flexible Context-aware Pervasive Alert Generation System

This paper presents a proposal for a context-aware framework for alert generation. The framework is based on a general purpose architecture integrating three core technologies: ontology representation, multi-agent paradigm and rule-based logic. The system is very efficient and versatile and its customization to new scenarios requires a very reduced effort, substantially limited to the update/ex...

متن کامل

A semantic-aware role-based access control model for pervasive computing environments

Access control in open and dynamic Pervasive Computing Environments (PCEs) is a very complex mechanism and encompasses various new requirements. In fact, in such environments, context information should be used in access control decision process; however, it is not applicable to gather all context information completely and accurately all the time. Thus, a suitable access control model for PCEs...

متن کامل

Context-aware Modeling for Spatio-temporal Data Transmitted from a Wireless Body Sensor Network

Context-aware systems must be interoperable and work across different platforms at any time and in any place. Context data collected from wireless body area networks (WBAN) may be heterogeneous and imperfect, which makes their design and implementation difficult. In this research, we introduce a model which takes the dynamic nature of a context-aware system into consideration. This model is con...

متن کامل

A Policy Model and Framework for Context-Aware Access Control to Information Resources

In today’s dynamic ICT environments, the ability to control users’ access to information resources and services becomes ever important. On the one hand, it should adapt to the users’ changing needs; on the other hand, it should not be compromised. Therefore, it is essential to have a flexible specification of access control polices, incorporating dynamically changing context information. The ba...

متن کامل

Context-aware Alert Verification for Network Security using the Extension Method based on Basic-Elements

As for network security, post-IDS alert analysis has become a fashion in view of collaboration and correlation, and context-aware alert verification is one of the main solutions. In order to guarantee a unified representation of related information and knowledge, this paper tries to introduce basic-elements and the extension method into the study on context-aware alert verification. This paper ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013