An ontology-driven approach applied to information security

Artem Vorobiev, Nargiza Bekmamedova · Swinburne figshare (Swinburne University of Technology) · 2010

Software systems have become highly distributed and complex involving independent components working together towards achieving systems ’ goals. Meanwhile, security attacks against such systems have increased to become more sophisticated and difficult to detect and withstand. In this paper, we argue that the collaboration of a system’s constituent components is a better way to detect and withstand this new generation of security attacks including multi-phased distributed attacks and various flooding distributed denial of service attacks. In order to achieve the collaborative intrusion detection and defenses in distributed environments, the system and its constituent components should have a common mechanism to share the collected knowledge about security attacks and counter measures. Thus, we develop and apply security ontologies that will serve as the common vocabulary that is understandable for both humans and software agents to share and analyse the received information. In particular, several security ontologies are introduced including the security attack ontology, the defence ontology, the asset-vulnerability ontology, the algorithm-standard ontology, and the security function ontology. In conclusion, we demonstrate the applicability of our approach with a case study illustrating the Mitnick attack.

Read the paper · More papers on PaperTik