Toward an efficient ontology-based event correlation in SIEM
Conference paper
Kenazag, T. and Aiash, M. 2016. Toward an efficient ontology-based event correlation in SIEM. 7th International Conference on Ambient Systems, Networks and Technologies (ANT2016). Madrid, Spain 23 - 26 May 2016 Elsevier. pp. 139-146 https://doi.org/10.1016/j.procs.2016.04.109
Type | Conference paper |
---|---|
Title | Toward an efficient ontology-based event correlation in SIEM |
Authors | Kenazag, T. and Aiash, M. |
Abstract | Cooperative intrusion detection use several intrusion detection systems (IDS) and analyzers in order to build a reliable overview of the monitored system trough a central security information and event management system (SIEM). In such environment, the definition of a shared vocabulary describing the exchanged information between tools is prominent. Since these pieces of information are structured, we propose in this paper to use an ontological representation based on Description Logics (DLs) which is a powerful tool for knowledge representation. Moreover, DLs are able to ensure a decidable reasoning. An alert correlation prototype is presented using this ontology, and an illustrative attack scenario is carried out to show the usefulness of the proposed ontology |
Conference | 7th International Conference on Ambient Systems, Networks and Technologies (ANT2016) |
Page range | 139-146 |
ISSN | 1877-0509 |
Publisher | Elsevier |
Publication dates | |
Online | 12 May 2016 |
26 Apr 2016 | |
Publication process dates | |
Deposited | 07 Jun 2017 |
Accepted | 21 Feb 2016 |
Output status | Published |
Publisher's version | License |
Copyright Statement | © 2016 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY-NC-ND license |
Digital Object Identifier (DOI) | https://doi.org/10.1016/j.procs.2016.04.109 |
Language | English |
Book title | Procedia Computer Science, Vol 83: The 7th International Conference on Ambient Systems, Networks and Technologies (ANT 2016) / The 6th International Conference on Sustainable Energy Information Technology (SEIT-2016) / Affiliated Workshops |
https://repository.mdx.ac.uk/item/86zx1
Download files
71
total views17
total downloads3
views this month1
downloads this month