Title :
Security Alert Management System for Internet Data Center Based on ISO/IEC 27001 Ontology
Author :
Tsang, Terry M F ; Yeung, Thomas M W ; Chiu, Dickson K W ; Hu, Haiyang ; Zhuang, Yi ; Hu, Hua
Author_Institution :
Dept. of Comput. Sci., Hong Kong Baptist Univ., Hong Kong, China
Abstract :
Internet Data Centers (IDC) emerge as a major network service platform to converge Internet related services and applications to one location, managing servers, networks, together with valuable and sensitive data of many enterprises. Therefore, an appropriate security approach is essential. Intrusion Detection Systems (IDS) are often deployed in IDC as a security measure to detect real-time intrusions and alert system administrators to take proper handling actions. However, a large number of low-level alerts lacking of classification make their management difficult. To tackle this problem, we propose a Security Alert Management System (SAMS) in which alerts generated by each IDS undergo alert aggregation. By incorporating ISO/IEC 27001 requirements into the ontology, our system classifies and aggregates alerts from multiple sources, providing a consolidated view of security incidents which are compliant with the ISO/IEC 27001 standard. We further facilitate effective handling of security alerts with different urgency classifications via an Alert Management System (AMS).
Keywords :
IEC standards; ISO standards; Internet; computer centres; security of data; ISO/IEC 27001 ontology; ISO/IEC 27001 requirements; ISO/IEC 27001 standard; Internet data centers; Internet related services; alert system administrators; intrusion detection systems; low-level alerts; network service platform; real-time intrusions; security alert management system; security approach; security measure; IEC standards; ISO standards; Internet; Monitoring; Ontologies; Security; Servers; Alert Aggregation; Alert Management System; Security Alerts; Security Ontology;
Conference_Titel :
e-Business Engineering (ICEBE), 2010 IEEE 7th International Conference on
Conference_Location :
Shanghai
Print_ISBN :
978-1-4244-8386-0
Electronic_ISBN :
978-0-7695-4227-0
DOI :
10.1109/ICEBE.2010.78