Title :
Using semantic networks to counter cyber threats
Author :
He, Peng ; Karabatis, George
Author_Institution :
Dept. of Inf. Syst., Univ. of Maryland, Baltimore, MD, USA
Abstract :
Intrusion detection is one of the most challenging tasks and of highest priority in the cyber security field; however, traditional intrusion detection techniques often fail to handle the complex and uncertain network attack correlation tasks. We propose the usage of semantic networks that build relationships among network attacks and assist in automatically identifying and predicting related attacks. Also, our method can increase the precision in detecting probable attacks. Experimental results show that our Semantic Network using the Anderberg similarity measure performs better in terms of precision and recall compared to existing correlation approaches in the cyber security domain. Specifically, our contributions are as follows: (1) We automatically construct a first mode Semantic Network from characterizing features of network attacks using similarity. (2) The first mode semantic network is calibrated by adding external semantic rules provided by domain experts, in order to generate a more adaptable second mode semantic network. (3) We evaluated the prediction capability of the semantic networks by experimenting with various similarity measures including Anderberg, Jaccard, Simple Matching and traditional correlation coefficients; we discovered that the “Anderberg” similarity coefficients outperform all other tested similarity measures in terms of precision and recall.
Keywords :
security of data; semantic networks; Anderberg correlation coefficients; Jaccard correlation coefficients; Simple Matching correlation coefficients; automatic attack identification; automatic attack prediction; complex network attack correlation tasks; cyber security domain; cyber threats; external semantic rules; first-mode semantic network; intrusion detection; precision; recall; second-mode semantic network; uncertain network attack correlation tasks; Computer security; Correlation; Educational institutions; Intrusion detection; Semantics; USA Councils;
Conference_Titel :
Intelligence and Security Informatics (ISI), 2012 IEEE International Conference on
Conference_Location :
Arlington, VA
Print_ISBN :
978-1-4673-2105-1
DOI :
10.1109/ISI.2012.6284294