Back to Search Start Over

A Semantic Approach to Situational Awareness for Intrusion Detection

Authors :
More, Sumit
Mathews, M. Lisa
Joshi, Anupam
Finin, Tim
Publication Year :
2012
Publisher :
National Coordination Office for Networking and Information Technology Research and Development, 2012.

Abstract

We describe a situation-aware intrusion detection system that integrates heterogeneous sources of information to build and maintain a semantically rich knowledge-base about cyber threats and vulnerabilities. Most current intrusion detection and prevention systems rely on signature-based approaches to detect attacks. When an attack signature is not available, such as for a new exploit or a significantly modified known one, such systems are much less effective. Moreover, these intrusion detection systems are point-based solutions which do not make effective use of heterogeneous data sources, which can provide important information related to intrusions which are not yet available as signature patterns. This information can also help detect low-and-slow attacks in which small intrusions that are spatially and temporally apart combine to build a more elaborate attack.

Details

Language :
English
Database :
OpenAIRE
Accession number :
edsair.doi...........ad518c544207c65489dd9f71bc140760
Full Text :
https://doi.org/10.13016/m2m61bt50