As for network security, post-IDS alert analysis has become a fashion in view of collaboration and correlation, and context-aware alert verification is one of the main solutions. In order to guarantee a unified representation of related information and knowledge, this paper tries to introduce basic-elements and the extension method into the study on context-aware alert verification. This paper then proposes the use of basic-elements to realize the formal presentation of alert information and context information in a unified manner, and applies the extension method based on basic-elements for context-aware alert verification by utilizing the extension set and the extension analysis. The evaluation result of validation scenarios shows that, the proposed approach prospects a formalized way to context-aware alert verification for network security with an appropriate use of the extension method based on basic-elements.
목차
Abstract 1. Introduction 2. Formal Representations of Alert Information and ContextInformation based on Basic-elements 2.1. Formalization of Security Information based on Basic-elements 2.2. Formalization of Alert Information for Network Security using Affair-elements 2.3. Formalization of Context Information for Network Security using Matter-elements 3. Application of the Extension Set for Context-aware Alert Verification 3.1. The Extension Set Point of View for Context-aware Alert Verification 3.2. State Transition for Network Security using the Extension Set 4. Application of the Extension Analysis based on Divergence-tree forContext-aware alert Verification 4.1. Divergence-tree for Extension Analysis 4.2. Validation Scenarios 5. Conclusions Acknowledgements References
보안공학연구지원센터(IJUNESST) [Science & Engineering Research Support Center, Republic of Korea(IJUNESST)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of u- and e- Service, Science and Technology
간기
격월간
pISSN
2005-4246
수록기간
2008~2016
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of u- and e- Service, Science and Technology Vol.6 No.1