The construction of an integrated solution for cyberspace defense with dynamic, flexible, and intelligent features is a new idea. To solve the problem whereby traditional static protection methods cannot respond to va...The construction of an integrated solution for cyberspace defense with dynamic, flexible, and intelligent features is a new idea. To solve the problem whereby traditional static protection methods cannot respond to various network attacks or security demands in an adversarial network environment in time, and to form a complete integrated solution from “threat discovery” to “decision-making generation,” we propose an ontology-based security model, Onto CSD, for an integrated solution of cyberspace defense that uses Web ontology language(OWL) to represent the ontology classes and relationships of threat monitoring, decision-making, response, and defense in cyberspace, and uses semantic Web rule language(SWRL) to design the defensive reasoning rules. Onto CSD can discover potential relationships among network attacks, vulnerabilities, the security state, and defense strategies. Further, an artificial intelligence(AI) expert system based on case-based reasoning(CBR) is used to quickly generate a detailed and comprehensive decision-making scheme. Finally, through Kendall ' s coefficient of concordance(W) and four experimental cases in a typical computer network defense(CND) system, which reasons on represented facts and the ontology, Onto CSD ' s consistency and its feasibility to solve the issues in the field of cyberspace defense are validated. Onto CSD supports automatic association and reasoning, and provides an integrated solution framework of cyberspace defense.展开更多
文摘The construction of an integrated solution for cyberspace defense with dynamic, flexible, and intelligent features is a new idea. To solve the problem whereby traditional static protection methods cannot respond to various network attacks or security demands in an adversarial network environment in time, and to form a complete integrated solution from “threat discovery” to “decision-making generation,” we propose an ontology-based security model, Onto CSD, for an integrated solution of cyberspace defense that uses Web ontology language(OWL) to represent the ontology classes and relationships of threat monitoring, decision-making, response, and defense in cyberspace, and uses semantic Web rule language(SWRL) to design the defensive reasoning rules. Onto CSD can discover potential relationships among network attacks, vulnerabilities, the security state, and defense strategies. Further, an artificial intelligence(AI) expert system based on case-based reasoning(CBR) is used to quickly generate a detailed and comprehensive decision-making scheme. Finally, through Kendall ' s coefficient of concordance(W) and four experimental cases in a typical computer network defense(CND) system, which reasons on represented facts and the ontology, Onto CSD ' s consistency and its feasibility to solve the issues in the field of cyberspace defense are validated. Onto CSD supports automatic association and reasoning, and provides an integrated solution framework of cyberspace defense.