A semantic web approach to share alerts among Security Information Management Systems

Abstract

This paper presents a semantic web-based architecture to share alerts among Security Information Management Systems (SIMS). Such architecture is useful if two or more SIMS from different domains need to know information about alerts happening in the other domains, which is useful for an early response to network incidents. For this, an ontology has been defined to describe the knowledge base of each SIMS that contains the security alerts. These knowledge bases can be queried from other SIMS, using standard semantic web protocols. Two modules have been implemented: one to insert the new security alerts in the knowledge base, and another one to query such knowledge bases. The performance of both modules has been evaluated, providing some results.

5 Figures and Tables

Cite this paper

@inproceedings{Vergara2009ASW, title={A semantic web approach to share alerts among Security Information Management Systems}, author={Jorge E. L{\'o}pez de Vergara and V{\'i}ctor A. Villagr{\'a} and Pilar Holgado and Elena de Frutos and Ivan Sanz}, year={2009} }