A Graph-based Representation of Relations in Network Security Alert Sharing Platforms

Warning

This publication doesn't include Faculty of Economics and Administration. It includes Institute of Computer Science. Official publication website can be found on muni.cz.
Authors

HUSÁK Martin ČERMÁK Milan

Year of publication 2017
Type Article in Proceedings
Conference 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM)
MU Faculty or unit

Institute of Computer Science

Citation
Web http://ieeexplore.ieee.org/document/7987399/
Doi http://dx.doi.org/10.23919/INM.2017.7987399
Field Informatics
Keywords graph;security alert;information sharing
Attached files
Description In this paper, we present a framework for graph-based representation of relation between sensors and alert types in a security alert sharing platform. Nodes in a graph represent either sensors or alert types, while edges represent various relations between them, such as common type of reported alerts or duplicated alerts. The graph is automatically updated, stored in a graph database, and visualized. The resulting graph will be used by network administrators and security analysts as a visual guide and situational awareness tool in a complex environment of security alert sharing.
Related projects:

You are running an old browser version. We recommend updating your browser to its latest version.