Memorias de investigación
Artículos en revistas:
Use of ontologies for the definition of alerts and policies in a network security platform
Año:2009

Áreas de investigación
  • Telemática

Datos
Descripción
A quick and efficient reaction to an attack is important to address the evolution of security incidents in current communication networks. The ReD (Reaction after Detection) project¿s aim is to design solutions that enhance the detection/reaction security process. This will improve the overall resilience of IP networks to attacks, helping telecommunication and service providers to maintain sufficient quality of service to comply with service level agreements. A main component within this project is in charge of instantiating new security policies that counteract the network attacks. This paper proposes an ontologybased methodology for the instantiation of these security policies. This approach provides a way to map alerts into attack contexts, which are later used to identify the policies to be applied in the network to solve the threat. For this, ontologies to describe alerts and policies are defined, using inference rules to perform such mappings. These ontologies are semantic representations of IDMEF alerts and ORBAC policies. Finally, this approach is applied in a Voice over IP use case, illustrating the mapping process.
Internacional
Si
JCR del ISI
No
Título de la revista
Journal of Networks
ISSN
1796-2056
Factor de impacto JCR
0
Información de impacto
Volumen
4
DOI
Número de revista
8
Desde la página
720
Hasta la página
733
Mes
OCTUBRE
Ranking

Esta actividad pertenece a memorias de investigación

Participantes
  • Autor: Antony Martin Alcatel-Lucent Bell Labs
  • Autor: Marie-Noëlle Lepareux Thales Communications
  • Autor: Samuel Dubus Alcatel-Lucent Bell Labs
  • Autor: Enrique Vazquez Gallo UPM
  • Autor: Jorge Enrique Lopez de Vergara UAM

Grupos de investigación, Departamentos, Centros e Institutos de I+D+i relacionados
  • Creador: Grupo de Investigación: Redes y Servicios de Telecomunicación e Internet
  • Departamento: Ingeniería de Sistemas Telemáticos