首页> 外文期刊>International journal of data mining, modelling and management >An ontology-based modelling and reasoning for alerts correlation
【24h】

An ontology-based modelling and reasoning for alerts correlation

机译:基于本体的建模和推理,用于报警相关性

获取原文
获取原文并翻译 | 示例
       

摘要

SIEM is a modern and powerful security tool thanks to several functions that it provides to take benefit of collected data, such as normalisation and aggregation. The main important function is events correlation, when security operators can get a precise and quick picture about threats and attacks in real-time. The quality of that picture depends on the efficiency of the adopted reasoning approach to putting together pieces of information provided by several analysers. In this paper, we propose a semantic approach based on description logics (DLs) which is a powerful tool for knowledge representation and reasoning. Indeed, ontology provides a comprehensive environment to represent information for intrusion detection and allows easy maintaining of information or adding new ones. We implemented a rule-based engine for alert correlation based on the proposed ontology and two attack scenarios are carried out to show the usefulness of our approach.
机译:暹粒是一种现代而强大的安全工具,它还提供了它提供的若干功能,以利用收集的数据,例如归一化和聚合。主要的重要功能是事件相关性,当安全运算符可以获得关于威胁和攻击的精确和快速的图像实时。该图片的质量取决于采用的推理方法的效率,将多个分析仪提供的信息汇集在一起​​。在本文中,我们提出了一种基于描述逻辑(DLS)的语义方法,这是一个有关知识表示和推理的强大工具。实际上,本体提供了全面的环境,可以表示入侵检测信息,并允许容易地维护信息或添加新的环境。我们在基于所提出的本体学和两个攻击方案的情况下实现了基于规则的引擎,以显示我们方法的有用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号