{"title":"Ontology Oriented Threat Detection System (OOTDS)","authors":"K. Banczyk, H. Krawczyk","doi":"10.1109/DepCoS-RELCOMEX.2009.45","DOIUrl":null,"url":null,"abstract":"The paper discusses the design of a general purpose ontology oriented threat detection system (OOTDS) for environments monitored by sensors. The sensors are assumed to continually provide OOTDS with events reflecting changes in the environment. OOTDS performs event analysis using a network of asynchronous blocks with increasing complexity. Front blocks convert sensor specific events to a unified form. A suggestion block provides hints for threat assessment based on a set of rules. The core threat detection block estimates probabilities of the suggested threats using Multi-Entities Bayesian Networks (MEBN) logic inference based on facts resulting from observed events and knowledge stored in an environment specific threat detection ontology (TDO). Threats with sufficiently high probability levels result in notifications sent to concerned users.The paper defines main OOTDS goals and presents its architecture followed by a short introduction to MEBN logic and an exemplary OOTDS application with a usage scenario.","PeriodicalId":185730,"journal":{"name":"2009 Fourth International Conference on Dependability of Computer Systems","volume":"107 5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-06-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 Fourth International Conference on Dependability of Computer Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/DepCoS-RELCOMEX.2009.45","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
The paper discusses the design of a general purpose ontology oriented threat detection system (OOTDS) for environments monitored by sensors. The sensors are assumed to continually provide OOTDS with events reflecting changes in the environment. OOTDS performs event analysis using a network of asynchronous blocks with increasing complexity. Front blocks convert sensor specific events to a unified form. A suggestion block provides hints for threat assessment based on a set of rules. The core threat detection block estimates probabilities of the suggested threats using Multi-Entities Bayesian Networks (MEBN) logic inference based on facts resulting from observed events and knowledge stored in an environment specific threat detection ontology (TDO). Threats with sufficiently high probability levels result in notifications sent to concerned users.The paper defines main OOTDS goals and presents its architecture followed by a short introduction to MEBN logic and an exemplary OOTDS application with a usage scenario.