An ontology-based model for SIEM environments

  • Gustavo Gonzalez Granadillo
  • , Yosra Ben Mustapha
  • , Nabil Hachem
  • , Herve Debar

Research output: Contribution to journalConference articlepeer-review

Abstract

The management of security events, from the analysis of attacks and risk to the selection of appropriate countermeasures, has become a major concern for security analysts and IT administrators. Furthermore, network and system devices are designed to be heterogeneous, with different characteristics and functionalities that increase the difficulty of these tasks. This paper introduces an ontology-driven approach to address the aforementioned problems. The proposed model takes into account the two main aspects of this field, the information that is manipulated by SIEM environments and the operations that are applied to this information, in order to reach the desired goals. We present a case study on Botnets to illustrate the utilization of our model.

Original languageEnglish
Pages (from-to)148-155
Number of pages8
JournalLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume99 LNICST
DOIs
Publication statusPublished - 7 Nov 2012
EventJoint 7th International Conference on Global Security, Safety and Sustainability, ICGS3 2011, and the 4th Conference on e-Democracy - Thessaloniki, Greece
Duration: 24 Aug 201126 Aug 2011

Keywords

  • Data Model
  • Ontology
  • SIEM

Fingerprint

Dive into the research topics of 'An ontology-based model for SIEM environments'. Together they form a unique fingerprint.

Cite this