作者
Gustavo Gonzalez Granadillo, Yosra Ben Mustapha, Nabil Hachem, Herve Debar
发表日期
2012/1/1
期刊
International Journal of Electronic Security and Digital Forensics 7
卷号
4
期号
2-3
页码范围
104-123
出版商
Inderscience Publishers Ltd
简介
The management of security events, from the risk analysis to the selection of appropriate countermeasures, has become a major concern for security analysts and IT administrators. Furthermore, the fact that network and system devices are heterogeneous, increases the difficulty of these administrative tasks. This paper introduces an ontology-driven approach to address the aforementioned problems. The proposed model takes into account two aspects: the information and the operations that are manipulated by SIEM environments in order to reach the desired goals. The model uses ontologies to provide simplicity on the description of concepts, relationships and instances of the security domain. The semantics web rule languages are used to describe the logic rules needed to infer relationships among individuals and classes. A case study on Botnets is presented at the end of this paper to illustrate a concrete …
引用总数
20132014201520162017201820192020202120222023214233211
学术搜索中的文章
G Gonzalez Granadillo, Y Ben Mustapha, N Hachem… - International Journal of Electronic Security and Digital …, 2012