An ontology-based approach to react to network attacks

  • Nora Cuppens-Boulahia
  • , Frédéric Cuppens
  • , Fabien Autrel
  • , Hervé Debar

Research output: Contribution to journalArticlepeer-review

Abstract

Intrusion detection requirements enforced by Intrusions Detection Systems (IDSs) are generally considered independently from the remainder of the security policy. Our approach is to consider that intrusion detection requirements are actually a part of the access control policy. This provides means to formally specify in a reaction policy what should happen in case of intrusion. It is then possible to integrate these requirements into a deploying process in order to automatically configure security components. In this paper, we propose a contextual and ontology-based approach to express and instantiate this reaction policy. We then define a reaction process based on the concepts of dynamic threat organisation and threat contexts and a set of rules used to map alerts onto threat contexts to perform the instantiation of the policy-based reaction in response to the detected intrusion.

Original languageEnglish
Pages (from-to)280-305
Number of pages26
JournalInternational Journal of Information and Computer Security
Volume3
Issue number3-4
DOIs
Publication statusPublished - 1 Jan 2009

Keywords

  • Attack reaction
  • IDS
  • Intrusions detection systems
  • Ontology
  • OrBAC
  • Organisation based access controlled
  • Policy instantiation

Fingerprint

Dive into the research topics of 'An ontology-based approach to react to network attacks'. Together they form a unique fingerprint.

Cite this