• DocumentCode
    614053
  • Title

    Behavior Ontology: A Framework to Detect Attack Patterns for Security

  • Author

    Sujeong Woo ; Jinho On ; Moonkun Lee

  • fYear
    2013
  • fDate
    25-28 March 2013
  • Firstpage
    738
  • Lastpage
    743
  • Abstract
    This paper presents a new method to detect attack patterns in security-critical systems, based on a new notion of Behavior Ontology. Generally security-critical systems are large and complex, and are subject to be attacked by attackers in every possible way. Therefore it is very complicated to detect various attacks systematically in some semantic structure. This paper handles the complication with Behavior Ontology, where patterns of attacks in the systems are defined as a sequence of actions on class ontology for the systems. By the nature of the actions, the attack patterns can be abstracted in hierarchical order, forming a lattice or a lattice of lattices, based on inclusion relations. Once the behavior ontology for the attach patterns are defined, the attacks in the target systems can be detected both semantically and hierarchically in the structure of the ontology. Compared with other attack models, the analysis on the behavior ontology shows that the approach in the paper is very effective and efficient in time and space. The approach can be considered as the first attempt to detect attack patterns with the notion of behavior ontology.
  • Keywords
    ontologies (artificial intelligence); pattern recognition; safety-critical software; security of data; action sequence; attack model; attack pattern detection; behavior ontology; class ontology; hierarchical abstraction; inclusion relation; security-critical system; semantic structure; Conferences; Abstraction; Attack; Behavior Ontology; Meta-Model; Pattern; Security-Critical Systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops (WAINA), 2013 27th International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-1-4673-6239-9
  • Electronic_ISBN
    978-0-7695-4952-1
  • Type

    conf

  • DOI
    10.1109/WAINA.2013.42
  • Filename
    6550484