Contextual Intrusion Alerts for SCADA Networks


Autoria(s): Al Balushi, Abdullah Salim Ali; McLaughlin, Kieran; Sezer, Sakir
Data(s)

21/02/2016

Resumo

The complexity of modern SCADA networks and their associated cyber-attacks requires an expressive but flexible manner for representing both domain knowledge and collected intrusion alerts with the ability to integrate them for enhanced analytical capabilities and better understanding of attacks. This paper proposes an ontology-based approach for contextualized intrusion alerts in SCADA networks. In this approach, three security ontologies were developed to represent and store information on intrusion alerts, Modbus communications, and Modbus attack descriptions. This information is correlated into enriched intrusion alerts using simple ontology logic rules written in Semantic Query-Enhanced Web Rules (SQWRL). The contextualized alerts give analysts the means to better understand evolving attacks and to uncover the semantic relationships between sequences of individual attack events. The proposed system is illustrated by two use case scenarios.

Identificador

http://pure.qub.ac.uk/portal/en/publications/contextual-intrusion-alerts-for-scada-networks(eb3dc6de-c12a-403a-9503-e937482811a6).html

http://dx.doi.org/10.5220/0005745504570464

Idioma(s)

eng

Direitos

info:eu-repo/semantics/openAccess

Fonte

Al Balushi , A S A , McLaughlin , K & Sezer , S 2016 , Contextual Intrusion Alerts for SCADA Networks . in Proceedings of the 2nd International Conference on Information Systems Security and Privacy . pp. 457-464 , 2nd International Conference on Information Systems Security and Privacy , Rome , Italy , 19-21 February . DOI: 10.5220/0005745504570464

Tipo

contributionToPeriodical