Intrusion Alerts Correlation Model Based on XSWRL Ontology

Wan Li,Yan Zhu,Shengfeng Tian
DOI: https://doi.org/10.1109/IITA.2008.412
2008-01-01
Abstract:We propose a hierarchical compound alert correlation knowledge model which combines prerequisites and consequences of attacks and predefined attack scenarios, and introduces hierarchy to view security information from different levels. The model includes basic concepts and relationships that are extracted from attack knowledge. Then we propose an alert correlation ontology frame which bases on our hierarchical compound alert correlation knowledge model. Some basic classes and properties are defined in the ontology frame. After extending those basic classes and properties in our ontology frame according to attack scenarios, we get a practical alert correlation ontology knowledgebase. Finally we illustrate how to represent our hierarchical compound alert correlation knowledge model using our XSWRL ontology.
What problem does this paper attempt to address?