DocumentCode :
3427173
Title :
The Ontological Approach for SIEM Data Repository Implementation
Author :
Kotenko, Igor ; Polubelova, Olga ; Saenko, Igor
Author_Institution :
Lab. of Comput. Security Problems, St. Petersburg Inst. for Inf. & Autom. (SPIIRAS), St. Petersburg, Russia
fYear :
2012
fDate :
20-23 Nov. 2012
Firstpage :
761
Lastpage :
766
Abstract :
The technology of Security Information and Event Management (SIEM) becomes one of the most important research applications in the area of computer network security, including distributed networks of internet enabled objects (as in the Internet of Things). The overall functionality of SIEM systems depends largely on the quality of solutions implemented at the data storage level, which is purposed for the representation of heterogeneous security events, their storage in the data repository and the extraction of relevant data for the analytical modules of SIEM systems. An ontological approach at present becomes more applicable for realizing these tasks in various spheres of information security. The paper discusses the possibilities of applying the ontological approach for implementation of the data repository of SIEM systems for distributed networks of Internet enabled objects. Based on the analysis of existing SIEM systems and standards, the choice of ontological approach is done, an example of the ontological data model of vulnerabilities is presented, a hybrid architecture of the ontological repository is proposed and the issues of developing and testing the repository for attack modelling and secure evaluation tasks are discussed.
Keywords :
Internet; computer network security; ontologies (artificial intelligence); Internet enabled objects; SIEM data repository implementation; computer network security; data storage level; distributed networks; heterogeneous security events; information security; ontological approach; ontological repository; secure evaluation tasks; security information and event management; Computer architecture; Data models; Internet; Ontologies; Security; Software; Standards; data model; data representation; logical inference; ontology; repository; security information and event management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Green Computing and Communications (GreenCom), 2012 IEEE International Conference on
Conference_Location :
Besancon
Print_ISBN :
978-1-4673-5146-1
Type :
conf
DOI :
10.1109/GreenCom.2012.125
Filename :
6468405
Link To Document :
بازگشت