Building a framework for network security situation awareness

Manpreet Singh, Pardeep Bhandari · International Conference on Computing for Sustainable Global Development · 2016

The number of devices on the network is increasing at a veryfast pace. The Internet of Things (IoT) is expected to include over 1.5 billion devices by end of year 2015. In addition to big volume of devices, more serious problem to be tackled in NSSA is unchecked generation of new network data models, services and protocols. Various approaches for network security have been proposed and being used like packet filtering, IDS and more recently IPS. The common problems of these above approaches are; these mechanisms are not aware of the resources they are protecting; mechanisms are independent of the context of their application; their working is common to every kind of environment, also these approaches do not adapt to the changing environment. To solve the problems of traditional approaches of network security, a formal model is required to represent entities of a network. The model should have the extensibility to accommodate new entities, to represent the relationships among the entities and also adapt to configuration changes in the network. Another issue is to handle heterogeneous data to get a holistic view of the network security. Data produced whether net flow or produced by various sensors in the network is heterogeneous in nature. The model should be able to handle such heterogeneity in data and should provide mechanism for automated fusion and processing of the network data. This is the prime requirement for perception and comprehension of the network security. To deal with these issues network management must be dynamic to accommodate these changes. In this paper we have proposed semantic web based framework for network security situation awareness.

Read the paper · More papers on PaperTik