|
Frontiers of Information Technology & Electronic Engineering
ISSN 2095-9184 (print), ISSN 2095-9230 (online)
2024 Vol.25 No.9 P.1209-1225
OntoCSD: an ontology-based security model for an integrated solution of cyberspace defense
Abstract: The construction of an integrated solution for cyberspace defense with dynamic, flexible, and intelligent features is a new idea. To solve the problem whereby traditional static protection methods cannot respond to various network attacks or security demands in an adversarial network environment in time, and to form a complete integrated solution from “threat discovery” to “decision-making generation,” we propose an ontology-based security model, OntoCSD, for an integrated solution of cyberspace defense that uses Web ontology language (OWL) to represent the ontology classes and relationships of threat monitoring, decision-making, response, and defense in cyberspace, and uses semantic Web rule language (SWRL) to design the defensive reasoning rules. OntoCSD can discover potential relationships among network attacks, vulnerabilities, the security state, and defense strategies. Further, an artificial intelligence (AI) expert system based on case-based reasoning (CBR) is used to quickly generate a detailed and comprehensive decision-making scheme. Finally, through Kendall’s coefficient of concordance (W) and four experimental cases in a typical computer network defense (CND) system, which reasons on represented facts and the ontology, OntoCSD’s consistency and its feasibility to solve the issues in the field of cyberspace defense are validated. OntoCSD supports automatic association and reasoning, and provides an integrated solution framework of cyberspace defense.
Key words: Cyberspace defense; Integrated solution; Ontology; Case-based reasoning (CBR); Computer network defense (CND)
1电子科技大学成都学院计算机学院,中国成都市,610731
2西北工业大学网络空间安全学院,中国西安市,710000
3中国电子科技网络信息安全有限公司,中国成都市,610000
摘要:构建动态、灵活、智能的网络空间防御综合解决方案是一种新理念。为了解决传统静态防护方法在网络对抗环境下无法及时响应各种网络攻击或安全需求的问题,形成从"威胁发现"到"决策生成"的完整集成解决方案,我们提出一种基于本体的安全模型-OntoCSD,该模型使用Web本体语言来表示网络空间威胁监测、决策、响应、防御过程中所涉及的本体类和关系,并使用语义Web规则语言来设计防御推理规则。OntoCSD可以发现网络攻击、漏洞、安全状态和防御策略之间的潜在关系。进一步地,利用基于案例推理的人工智能专家系统快速生成详细、全面的决策方案。最后,通过肯德尔一致性系数和典型计算机网络防御系统中四个基于表征事实和本体推理的实验案例,验证了OntoCSD解决网络空间防御领域问题的一致性和可行性。OntoCSD支持自动关联和推理,能够为网络空间防御提供整体解决方案框架。
关键词组:
References:
Open peer comments: Debate/Discuss/Question/Opinion
<1>
DOI:
10.1631/FITEE.2300662
CLC number:
TP393
Download Full Text:
Downloaded:
663
Download summary:
<Click Here>Downloaded:
122Clicked:
1135
Cited:
0
On-line Access:
2024-08-27
Received:
2023-10-17
Revision Accepted:
2024-05-08
Crosschecked:
2024-09-29