首页> 外文会议>Computational intelligence and its applications >Implementing a Semantic Approach for Events Correlation in SIEM Systems
【24h】

Implementing a Semantic Approach for Events Correlation in SIEM Systems

机译:在SIEM系统中实现事件关联的语义方法

获取原文
获取原文并翻译 | 示例

摘要

Efficient reasoning in intrusion detection needs to manipulate different information provided by several analyzers in order to build a reliable overview of the underlying monitored system trough a central security information and event management system (SIEM). SIEM provides many functions to take benefit of collected data, such as Normalization, Aggregation, Alerting, Archiving, Forensic analysis, Dashboards, etc. The most relevant function is Correlation, when we can get a precise and quick picture about threats and attacks in real time. Since information provided by SIEM is in general structured and can be given in XML, we propose in this paper to use an ontological representation based on Description Logics (DLs) which is a powerful tool for knowledge representation and reasoning. Indeed, Ontology provides a comprehensive environment to represent any kind of information in intrusion detection. Moreover, basing on DLs and rules, Ontology is able to ensure a decid-able reasoning. Basing on the proposed ontology, an alert correlation prototype is implemented and two attack scenarios are carried out to show the usefulness of the semantic approach.
机译:入侵检测中的有效推理需要操纵由多个分析器提供的不同信息,以便通过中央安全信息和事件管理系统(SIEM)建立基础受监视系统的可靠概览。 SIEM提供了许多功能来利用收集的数据,例如归一化,聚合,警报,归档,取证分析,仪表板等。最相关的功能是“相关性”,当我们可以准确,快速地了解真实的威胁和攻击时时间。由于SIEM提供的信息通常是结构化的,并且可以XML形式给出,因此我们在本文中建议使用基于描述逻辑(DL)的本体表示,这是用于知识表示和推理的强大工具。实际上,本体论提供了一个全面的环境来表示入侵检测中的任何类型的信息。此外,基于DL和规则,Ontology能够确保确定的推理。在提出的本体基础上,实现了一种预警相关原型,并通过两种攻击场景证明了语义方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号