DocumentCode
614053
Title
Behavior Ontology: A Framework to Detect Attack Patterns for Security
Author
Sujeong Woo ; Jinho On ; Moonkun Lee
fYear
2013
fDate
25-28 March 2013
Firstpage
738
Lastpage
743
Abstract
This paper presents a new method to detect attack patterns in security-critical systems, based on a new notion of Behavior Ontology. Generally security-critical systems are large and complex, and are subject to be attacked by attackers in every possible way. Therefore it is very complicated to detect various attacks systematically in some semantic structure. This paper handles the complication with Behavior Ontology, where patterns of attacks in the systems are defined as a sequence of actions on class ontology for the systems. By the nature of the actions, the attack patterns can be abstracted in hierarchical order, forming a lattice or a lattice of lattices, based on inclusion relations. Once the behavior ontology for the attach patterns are defined, the attacks in the target systems can be detected both semantically and hierarchically in the structure of the ontology. Compared with other attack models, the analysis on the behavior ontology shows that the approach in the paper is very effective and efficient in time and space. The approach can be considered as the first attempt to detect attack patterns with the notion of behavior ontology.
Keywords
ontologies (artificial intelligence); pattern recognition; safety-critical software; security of data; action sequence; attack model; attack pattern detection; behavior ontology; class ontology; hierarchical abstraction; inclusion relation; security-critical system; semantic structure; Conferences; Abstraction; Attack; Behavior Ontology; Meta-Model; Pattern; Security-Critical Systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications Workshops (WAINA), 2013 27th International Conference on
Conference_Location
Barcelona
Print_ISBN
978-1-4673-6239-9
Electronic_ISBN
978-0-7695-4952-1
Type
conf
DOI
10.1109/WAINA.2013.42
Filename
6550484
Link To Document