Search
2003 Volume 18
Article Contents
RESEARCH ARTICLE   Open Access    

Using DAML+OIL to classify intrusive behaviours

More Information
  • We have produced an ontology specifying a model of computer attack. Our ontology is based upon an analysis of over 4000 classes of computer intrusions and their corresponding attack strategies and is categorised according to system component targeted, means of attack, consequence of attack and location of attacker. We argue that any taxonomic characteristics used to define a computer attack be limited in scope to those features that are observable and measurable at the target of the attack. We present our model as a target-centric ontology that is to be refined and expanded over time. We state the benefits of forgoing dependence upon taxonomies in favour of ontologies for the classification of computer attacks and intrusions. We have specified our ontology using the DARPA Agent Markup Language+Ontology Inference Layer and have prototyped it using DAMLJessKB. We present our model as a target-centric ontology and illustrate the benefits of utilising an ontology in lieu of a taxonomy, by presenting a use-case scenario of a distributed intrusion detection system.
  • 加载中
  • Cite this article

    JEFFREY UNDERCOFFER, ANUPAM JOSHI, TIM FININ, JOHN PINKSTON. 2003. Using DAML+OIL to classify intrusive behaviours. The Knowledge Engineering Review. 18: doi: 10.1017/S0269888904000049
    JEFFREY UNDERCOFFER, ANUPAM JOSHI, TIM FININ, JOHN PINKSTON. 2003. Using DAML+OIL to classify intrusive behaviours. The Knowledge Engineering Review. 18: doi: 10.1017/S0269888904000049

Article Metrics

Article views(13) PDF downloads(21)

RESEARCH ARTICLE   Open Access    

Using DAML+OIL to classify intrusive behaviours

The Knowledge Engineering Review  18 Article number: 10.1017/S0269888904000049  (2003)  |  Cite this article

Abstract: We have produced an ontology specifying a model of computer attack. Our ontology is based upon an analysis of over 4000 classes of computer intrusions and their corresponding attack strategies and is categorised according to system component targeted, means of attack, consequence of attack and location of attacker. We argue that any taxonomic characteristics used to define a computer attack be limited in scope to those features that are observable and measurable at the target of the attack. We present our model as a target-centric ontology that is to be refined and expanded over time. We state the benefits of forgoing dependence upon taxonomies in favour of ontologies for the classification of computer attacks and intrusions. We have specified our ontology using the DARPA Agent Markup Language+Ontology Inference Layer and have prototyped it using DAMLJessKB. We present our model as a target-centric ontology and illustrate the benefits of utilising an ontology in lieu of a taxonomy, by presenting a use-case scenario of a distributed intrusion detection system.

    • © 2004 Cambridge University Press
  • About this article
    Cite this article
    JEFFREY UNDERCOFFER, ANUPAM JOSHI, TIM FININ, JOHN PINKSTON. 2003. Using DAML+OIL to classify intrusive behaviours. The Knowledge Engineering Review. 18: doi: 10.1017/S0269888904000049
    JEFFREY UNDERCOFFER, ANUPAM JOSHI, TIM FININ, JOHN PINKSTON. 2003. Using DAML+OIL to classify intrusive behaviours. The Knowledge Engineering Review. 18: doi: 10.1017/S0269888904000049
  • Catalog

      /

      DownLoad:  Full-Size Img  PowerPoint
      Return
      Return