节点文献
入侵检测报警聚合与关联系统设计与实现
Design and Implementation of Intrusion Detection Alerts Aggregation and Correlation System
【摘要】 入侵检测系统的大部分报警事件之间都存在某种联系,通过对这些报警的聚合与关联能够消除或减少重复报警,降低误报率及发现高层多步攻击策略。论文设计并实现了一种报警聚合与关联系统,系统主要包括报警聚合、报警校验、多步攻击报警关联和报告分析与规则控制等部分。实验证明:该系统能够减少报警数量,并能识别攻击意图,达到预警的目的。
【Abstract】 The alert events detected by Intrusion Detection System are usually interrelated in certain respects. Through aggregating and correlating of these alerts , the system can eliminate or reduce numbers of the same alerts , decrease false positive rate,and discover the high level multi- step attack policy. This paper presents an intrusion alerts aggregating and correlating system, which is mainly composed of aggregation analysis, alerts verification and multi- step attack correlation,etc. Experiments show that the system is effective in reducing the number of alerts,and can warn according to attack intention identified.
【Key words】 Intrusion detection; Alerts aggregation; Alerts Correlation; Alerts verification;
- 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2007年36期
- 【分类号】TP393.08
- 【被引频次】6
- 【下载频次】102