As computer technology evolves and the threat of computer crimes increases, the apprehension and preemption of such violations become more and more diffi cult and challenging. To date, it appears that completely preventing breaches of security is unrealistic. Therefore, we must try to detect and classify these intrusions as they occur so that immediate actions may be taken to repair the damage and prevent/urther harm. One attempt at classifying these intrusions is MITRE's Common Vulnerabilities and Exposures (eVE) list that provides a common name/or all publicly known security weaknesses. The CVE dictionary, however, is not taxonomy. The eVE list is organized in simple numerical order by date of acceptance. Each entry in the dictionary includes a unique eVE identification number, a text description of the vulnerability and any pertinent references. Creating a Self-Organizing Map (SOM) using the text description allows us to order attack profiles with common features in the same general area of the output space. Attacks in the general neighborhood of one another should be able to be mitigated by similar means. Plotting attacks on a SOM also enables us to visually examine the placement of an attack re14tive to the four common classes of at tacks {Denial of Service, Deception, Reconnaissance, and UnauthorizedAccess}. Many attacks have features in common with more than one of these c14sses rather than corresponding directly to a single class. We have developed an effective technique to classify new attacks using a unique taxonomy, which breaks down threats into the four general categories, and the SOM created by the baseline eVE descriptions.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.