DocumentCode
3128209
Title
Using semantic networks to counter cyber threats
Author
He, Peng ; Karabatis, George
Author_Institution
Dept. of Inf. Syst., Univ. of Maryland, Baltimore, MD, USA
fYear
2012
fDate
11-14 June 2012
Firstpage
184
Lastpage
184
Abstract
Intrusion detection is one of the most challenging tasks and of highest priority in the cyber security field; however, traditional intrusion detection techniques often fail to handle the complex and uncertain network attack correlation tasks. We propose the usage of semantic networks that build relationships among network attacks and assist in automatically identifying and predicting related attacks. Also, our method can increase the precision in detecting probable attacks. Experimental results show that our Semantic Network using the Anderberg similarity measure performs better in terms of precision and recall compared to existing correlation approaches in the cyber security domain. Specifically, our contributions are as follows: (1) We automatically construct a first mode Semantic Network from characterizing features of network attacks using similarity. (2) The first mode semantic network is calibrated by adding external semantic rules provided by domain experts, in order to generate a more adaptable second mode semantic network. (3) We evaluated the prediction capability of the semantic networks by experimenting with various similarity measures including Anderberg, Jaccard, Simple Matching and traditional correlation coefficients; we discovered that the “Anderberg” similarity coefficients outperform all other tested similarity measures in terms of precision and recall.
Keywords
security of data; semantic networks; Anderberg correlation coefficients; Jaccard correlation coefficients; Simple Matching correlation coefficients; automatic attack identification; automatic attack prediction; complex network attack correlation tasks; cyber security domain; cyber threats; external semantic rules; first-mode semantic network; intrusion detection; precision; recall; second-mode semantic network; uncertain network attack correlation tasks; Computer security; Correlation; Educational institutions; Intrusion detection; Semantics; USA Councils;
fLanguage
English
Publisher
ieee
Conference_Titel
Intelligence and Security Informatics (ISI), 2012 IEEE International Conference on
Conference_Location
Arlington, VA
Print_ISBN
978-1-4673-2105-1
Type
conf
DOI
10.1109/ISI.2012.6284294
Filename
6284294
Link To Document