Back to Search
Start Over
A Semantic Approach to Situational Awareness for Intrusion Detection
- Publication Year :
- 2012
- Publisher :
- National Coordination Office for Networking and Information Technology Research and Development, 2012.
-
Abstract
- We describe a situation-aware intrusion detection system that integrates heterogeneous sources of information to build and maintain a semantically rich knowledge-base about cyber threats and vulnerabilities. Most current intrusion detection and prevention systems rely on signature-based approaches to detect attacks. When an attack signature is not available, such as for a new exploit or a significantly modified known one, such systems are much less effective. Moreover, these intrusion detection systems are point-based solutions which do not make effective use of heterogeneous data sources, which can provide important information related to intrusions which are not yet available as signature patterns. This information can also help detect low-and-slow attacks in which small intrusions that are spatially and temporally apart combine to build a more elaborate attack.
- Subjects :
- cybersecurity
intrusion detection
UMBC Ebiquity Research Group
Semantic
Subjects
Details
- Language :
- English
- Database :
- OpenAIRE
- Accession number :
- edsair.doi...........ad518c544207c65489dd9f71bc140760
- Full Text :
- https://doi.org/10.13016/m2m61bt50