Skip to main content

An Ontology Based Approach for Host Intrusion Detection Systems

  • Conference paper
  • First Online:
Metadata and Semantic Research (MTSR 2017)

Part of the book series: Communications in Computer and Information Science ((CCIS,volume 755))

Included in the following conference series:

  • 1186 Accesses

Abstract

In recent years, cyber-attacks have emerged and these attacks result in serious consequences. In order to overcome these consequences, a fully-functioning and performance-improved intrusion detections systems are required. For this purpose, we used ontologies to provide semantic expressiveness and knowledge description for an intrusion detection system. In this work, a host intrusion detection system is implemented by using ontologies. The proposed system scans for malwares running on the operating system. Also, services and processes that are working on the system are scanned, and results are compared with the malware database. If any match occurs, the proposed system displays a malware list that matches with the information of that malware and where it is running. The proposed ontology based intrusion detection system aims to reduce the search time for malware scanning and to improve the performance of intrusion detection systems.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
$34.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

References

  1. Facebook Osquery, SQL powered operating system instrumentation, monitoring, and analytics. https://github.com/facebook/osquery. Accessed 08 July 2017

  2. Symantec: Security Response. https://www.symantec.com/security_response/landing/azlisting.jsp. Accessed 08 July 2017

  3. Undercoffer, J., Joshi, A., Pinkston, J.: Modeling computer attacks: an ontology for intrusion detection. In: Vigna, G., Kruegel, C., Jonsson, E. (eds.) RAID 2003. LNCS, vol. 2820, pp. 113–135. Springer, Heidelberg (2003). doi:10.1007/978-3-540-45248-5_7

    Chapter  Google Scholar 

  4. DAML + OIL Reference Description Homepage. https://www.w3.org/TR/daml+oil-reference. Accessed 08 July 2017

  5. OWL2 Homepage. https://www.w3.org/TR/owl2-overview/. Accessed 08 July 2017

  6. Khairkar, A.D.: Intrusion Detection System based on Ontology for Web Applications. Dissertation, Master of Technology, Computer Engineering, Department of Computer Engineering and Information Technology College of Engineering, Pune (2013)

    Google Scholar 

  7. Turner, C., Rolston, J., Richards, D., Joseph, A.: A rule status monitoring algorithm for rule-based intrusion detection and prevention systems. Procedia Comput. Sci. 95, 361–368 (2016)

    Article  Google Scholar 

  8. Deshmukh, R., Deshmukh, R., Manoj Sharma, M.: Rule-based and cluster-based intrusion detection technique for wireless sensor network. Int. J. Comput. Sci. Mobile Comput. 2(6), 200–208 (2013)

    Google Scholar 

  9. Gruber, T.R.: A translation approach to portable ontologies. Knowl. Acquisition 5(2), 199–220 (1993)

    Article  Google Scholar 

  10. Noy, N.F., McGuinness, D.L.: Ontology Development 101: A Guide to Creating Your First Ontology. http://protege.stanford.edu/publications/ontology_development/ontology101.pdf. Accessed 08 July 2017

  11. Apache Jena Homepage. https://jena.apache.org. Accessed 08 July 2017

  12. Kaitoy Pcap4J: A Java library for capturing, crafting, and sending packets. https://github.com/kaitoy/pcap4j. Accessed 08 July 2017

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Ozgu Can .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2017 Springer International Publishing AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Can, O., Unalir, M.O., Sezer, E., Bursa, O., Erdogdu, B. (2017). An Ontology Based Approach for Host Intrusion Detection Systems. In: Garoufallou, E., Virkus, S., Siatri, R., Koutsomiha, D. (eds) Metadata and Semantic Research. MTSR 2017. Communications in Computer and Information Science, vol 755. Springer, Cham. https://doi.org/10.1007/978-3-319-70863-8_8

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-70863-8_8

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-70862-1

  • Online ISBN: 978-3-319-70863-8

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics