Ontology for Detection of Web Attacks

Ashwini Khairkar, Deepak D. Kshirsagar, Sandeep Kumar · 2013

Intrusion Detection System (IDS) must reliably detect malicious activity. The expansion of web application also exponentially increases cyber threats. Current survey shows that application layer is more vulnerable to web attacks. There are more than 75% of attacks are deployed at application layer and out of that 90% are vulnerable to attacks. In this paper, we address issues of existing IDS i.e. low false positive rate, low false negative rate and data overload. We discuss about use of semantic web in the Intrusion Detection Systems. This article presents a proposition of using Semantic Web and Ontology concepts to define an approach to analyze Security logs with the goal to identify possible security issues. It extracts semantic relations between computer attacks and intrusions in an Intrusion Detection System. Ontology provides to enable, reuse of domain knowledge and it is also easier to understand and update legacy data.

Read the paper · More papers on PaperTik