Case Retrieval for Network Security Emergency Response Based on Description Logic

Abstract : Network security emergency response (NSER) is an important topic in information security. Nowadays, a large number of NSER systems and tools are developed, which can effectively detect part of security incidents and provide general best-practice guidelines for handling some type of security incidents, but not give a reasonable, fast, effective processing method for every security incidents in actual environment. An intelligent method based on case-based reasoning (CBR) and description logic (DL) is proposed for NSER. Firstly, a case base for NSER is organized in such a way that domain knowledge of NSER is described by the DL ALCO(D). Secondly, based on refinement operator and refinement graph in DLs, an algorithm for measuring the similarity of ALCO(D) concepts is designed and used for retrieving cases from the case base. It is demonstrated that our method can reuse past experiences on security incidents to generate response automatically.
Type de document :
Communication dans un congrès
Zhongzhi Shi; Zhaohui Wu; David Leake; Uli Sattler. 8th International Conference on Intelligent Information Processing (IIP), Oct 2014, Hangzhou, China. Springer, IFIP Advances in Information and Communication Technology, AICT-432, pp.284-293, 2014, Intelligent Information Processing VII. 〈10.1007/978-3-662-44980-6_32〉
Liste complète des métadonnées

Littérature citée [11 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01383343
Contributeur : Hal Ifip <>
Soumis le : mardi 18 octobre 2016 - 14:58:23
Dernière modification le : mardi 18 octobre 2016 - 15:08:49

Fichier

978-3-662-44980-6_32_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Fei Jiang, Tianlong Gu, Liang Chang, Zhoubo Xu. Case Retrieval for Network Security Emergency Response Based on Description Logic. Zhongzhi Shi; Zhaohui Wu; David Leake; Uli Sattler. 8th International Conference on Intelligent Information Processing (IIP), Oct 2014, Hangzhou, China. Springer, IFIP Advances in Information and Communication Technology, AICT-432, pp.284-293, 2014, Intelligent Information Processing VII. 〈10.1007/978-3-662-44980-6_32〉. 〈hal-01383343〉

Partager

Métriques

Consultations de la notice

86

Téléchargements de fichiers

31