D 2017

A Graph-based Representation of Relations in Network Security Alert Sharing Platforms

HUSÁK, Martin and Milan ČERMÁK

Basic information

Original name

A Graph-based Representation of Relations in Network Security Alert Sharing Platforms

Authors

HUSÁK, Martin and Milan ČERMÁK

Edition

Lisbon, 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), p. 891-892, 2 pp. 2017

Publisher

IEEE

Other information

Language

English

Type of outcome

Proceedings paper

Field of Study

Informatics

Country of publisher

United States of America

Confidentiality degree

is not subject to a state or trade secret

Publication form

electronic version available online

References:

Marked to be transferred to RIV

Yes

RIV identification code

RIV/00216224:14610/17:00094469

Organization

Ústav výpočetní techniky – Repository – Repository

ISBN

978-3-901882-89-0

EID Scopus

Keywords in English

graph;security alert;information sharing

Links

MUNI/A/0997/2016, interní kód Repo. VI20162019029, research and development project.
Changed: 4/9/2020 02:54, RNDr. Daniel Jakubík

Abstract

In the original language

In this paper, we present a framework for graph-based representation of relation between sensors and alert types in a security alert sharing platform. Nodes in a graph represent either sensors or alert types, while edges represent various relations between them, such as common type of reported alerts or duplicated alerts. The graph is automatically updated, stored in a graph database, and visualized. The resulting graph will be used by network administrators and security analysts as a visual guide and situational awareness tool in a complex environment of security alert sharing.

Files attached