Visible to the public Analysis System for Security Situation in Cyberspace Based on Knowledge Graph

TitleAnalysis System for Security Situation in Cyberspace Based on Knowledge Graph
Publication TypeConference Paper
Year of Publication2021
AuthorsKang, Ji, Sun, Yi, Xie, Hui, Zhu, Xixi, Ding, Zhaoyun
Conference Name2021 7th International Conference on Big Data and Information Analytics (BigDIA)
Date Publishedoct
KeywordsCorrelation, cyber security, cyber situation, Cyberspace, Human Behavior, Internet, intrusion detection system, Knowledge engineering, knowledge graph, policy-based governance, pubcrawl, resilience, Resiliency, security weaknesses, Soft sensors, Systematics, Web pages
AbstractWith the booming of Internet technology, the continuous emergence of new technologies and new algorithms greatly expands the application boundaries of cyberspace. While enjoying the convenience brought by informatization, the society is also facing increasingly severe threats to the security of cyberspace. In cyber security defense, cyberspace operators rely on the discovered vulnerabilities, attack patterns, TTPs, and other knowledge to observe, analyze and determine the current threats to the network and security situation in cyberspace, and then make corresponding decisions. However, most of such open-source knowledge is distributed in different data sources in the form of text or web pages, which is not conducive to the understanding, query and correlation analysis of cyberspace operators. In this paper, a knowledge graph for cyber security is constructed to solve this problem. At first, in the process of obtaining security data from multi-source heterogeneous cyberspaces, we adopt efficient crawler to crawl the required data, paving the way for knowledge graph building. In order to establish the ontology required by the knowledge graph, we abstract the overall framework of security data sources in cyberspace, and depict in detail the correlations among various data sources. Then, based on the \$$\backslash$mathbfOWL +$\backslash$mathbfSWRL\$ language, we construct the cyber security knowledge graph. On this basis, we design an analysis system for situation in cyberspace based on knowledge graph and the Snort intrusion detection system (IDS), and study the rules in Snort. The system integrates and links various public resources from the Internet, including key information such as general platforms, vulnerabilities, weaknesses, attack patterns, tactics, techniques, etc. in real cyberspace, enabling the provision of comprehensive, systematic and rich cyber security knowledge to security researchers and professionals, with the expectation to provide a useful reference for cyber security defense.
DOI10.1109/BigDIA53151.2021.9619719
Citation Keykang_analysis_2021