loading
Documents

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Abdullah Al Balushi ; Kieran McLaughlin and Sakir Sezer

Affiliation: Queens University Belfast, United Kingdom

ISBN: 978-989-758-167-0

Keyword(s): Security Ontology, Intrusion Detection System, Modbus TCP, Intrusion Alert Analysis.

Related Ontology Subjects/Areas/Topics: Internet Technology ; Intrusion Detection and Response ; Web Information Systems and Technologies

Abstract: The complexity of modern SCADA networks and their associated cyber-attacks requires an expressive but flexible manner for representing both domain knowledge and collected intrusion alerts with the ability to integrate them for enhanced analytical capabilities and better understanding of attacks. This paper proposes an ontology-based approach for contextualized intrusion alerts in SCADA networks. In this approach, three security ontologies were developed to represent and store information on intrusion alerts, Modbus communications, and Modbus attack descriptions. This information is correlated into enriched intrusion alerts using simple ontology logic rules written in Semantic Query-Enhanced Web Rules (SQWRL). The contextualized alerts give analysts the means to better understand evolving attacks and to uncover the semantic relationships between sequences of individual attack events. The proposed system is illustrated by two use case scenarios.

PDF ImageFull Text

Download
Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 54.174.43.27

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Al Balushi, A.; McLaughlin, K. and Sezer, S. (2016). Contextual Intrusion Alerts for Scada Networks - An Ontology based Approach for Intrusion Alerts Post Processing.In Proceedings of the 2nd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-167-0, pages 457-464. DOI: 10.5220/0005745504570464

@conference{icissp16,
author={Abdullah Al Balushi. and Kieran McLaughlin. and Sakir Sezer.},
title={Contextual Intrusion Alerts for Scada Networks - An Ontology based Approach for Intrusion Alerts Post Processing},
booktitle={Proceedings of the 2nd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2016},
pages={457-464},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0005745504570464},
isbn={978-989-758-167-0},
}

TY - CONF

JO - Proceedings of the 2nd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Contextual Intrusion Alerts for Scada Networks - An Ontology based Approach for Intrusion Alerts Post Processing
SN - 978-989-758-167-0
AU - Al Balushi, A.
AU - McLaughlin, K.
AU - Sezer, S.
PY - 2016
SP - 457
EP - 464
DO - 10.5220/0005745504570464

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.