creators_name: Saraydaryan, Jacques creators_name: Benali, Fatiha creators_name: Ubeda, Stéphane type: journalp datestamp: 2009-11-14 11:35:23 lastmod: 2011-03-11 08:57:31 metadata_visibility: show title: Comprehensive Security Framework for Global Threats Analysis ispublished: pub subjects: comp-sci-mach-dynam-sys full_text_status: public keywords: Security Information, Heterogeneity, Intrusion Detection, Behavioral Analysis, Ontology abstract: Cyber criminality activities are changing and becoming more and more professional. With the growth of financial flows through the Internet and the Information System (IS), new kinds of thread arise involving complex scenarios spread within multiple IS components. The IS information modeling and Behavioral Analysis are becoming new solutions to normalize the IS information and counter these new threads. This paper presents a framework which details the principal and necessary steps for monitoring an IS. We present the architecture of the framework, i.e. an ontology of activities carried out within an IS to model security information and User Behavioral analysis. The results of the performed experiments on real data show that the modeling is effective to reduce the amount of events by 91%. The User Behavioral Analysis on uniform modeled data is also effective, detecting more than 80% of legitimate actions of attack scenarios. date: 2009-08 date_type: published publication: J. Saraydaryan, F. Benali and S. Ubeda, "Comprehensive Security Framework for Global Threats Analysis", International Journal of Computer Science Issues, IJCSI, Volume 2, pp18-32, August 2009 volume: 2 publisher: International Journal of Computer Science Issues, IJCSI refereed: TRUE citation: Saraydaryan, Jacques and Benali, Fatiha and Ubeda, Stéphane (2009) Comprehensive Security Framework for Global Threats Analysis. [Journal (Paginated)] document_url: http://cogprints.org/6693/1/2-18-32.pdf