• DocumentCode
    3128209
  • Title

    Using semantic networks to counter cyber threats

  • Author

    He, Peng ; Karabatis, George

  • Author_Institution
    Dept. of Inf. Syst., Univ. of Maryland, Baltimore, MD, USA
  • fYear
    2012
  • fDate
    11-14 June 2012
  • Firstpage
    184
  • Lastpage
    184
  • Abstract
    Intrusion detection is one of the most challenging tasks and of highest priority in the cyber security field; however, traditional intrusion detection techniques often fail to handle the complex and uncertain network attack correlation tasks. We propose the usage of semantic networks that build relationships among network attacks and assist in automatically identifying and predicting related attacks. Also, our method can increase the precision in detecting probable attacks. Experimental results show that our Semantic Network using the Anderberg similarity measure performs better in terms of precision and recall compared to existing correlation approaches in the cyber security domain. Specifically, our contributions are as follows: (1) We automatically construct a first mode Semantic Network from characterizing features of network attacks using similarity. (2) The first mode semantic network is calibrated by adding external semantic rules provided by domain experts, in order to generate a more adaptable second mode semantic network. (3) We evaluated the prediction capability of the semantic networks by experimenting with various similarity measures including Anderberg, Jaccard, Simple Matching and traditional correlation coefficients; we discovered that the “Anderberg” similarity coefficients outperform all other tested similarity measures in terms of precision and recall.
  • Keywords
    security of data; semantic networks; Anderberg correlation coefficients; Jaccard correlation coefficients; Simple Matching correlation coefficients; automatic attack identification; automatic attack prediction; complex network attack correlation tasks; cyber security domain; cyber threats; external semantic rules; first-mode semantic network; intrusion detection; precision; recall; second-mode semantic network; uncertain network attack correlation tasks; Computer security; Correlation; Educational institutions; Intrusion detection; Semantics; USA Councils;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligence and Security Informatics (ISI), 2012 IEEE International Conference on
  • Conference_Location
    Arlington, VA
  • Print_ISBN
    978-1-4673-2105-1
  • Type

    conf

  • DOI
    10.1109/ISI.2012.6284294
  • Filename
    6284294