节点文献
网络安全协同防卫系统研究与实现
Research and Implementation of Network Security Cooperative Defense System
【摘要】 为了解决防卫体系中各安全模块缺乏协同控制以及不能有效发挥整体效应的问题,提出了一种基于代理的协同控制框架.将各个安全模块关联起来,以实现相互通信和协同工作.在此基础上,构建了包括预警定位、协同安全审计及态势评估、协同事故恢复、网络伪装等功能的网络安全协同防卫系统(NSCDS).以基于机器学习的系统调用序列审计模型为例,对关键技术模块进行了分析和验证,结果表明NSCDS软件在百兆级带宽下,安全审计预警漏报率小于6%,误报率小于8%,各功能模块工作稳定且配合正常,充分显示出系统的综合优势,实现了网络安全多层次、全方位的协同防卫目标.
【Abstract】 A novel network security cooperative defense technology is studied and a cooperative control framework based on agent mechanism is proposed to solve the lack of cooperative control and whole effect in traditional defense systems.The technology supports both IPv4 and IPv6 protocols and security modules in the framework are associated with each other to accomplish communication and work together.Furthermore,a network security cooperative defense system is composed and the key functions that support the early-alert,audit,accident recovery,network camouflage and so on are also achieved.The pivotal research is emphasized on the key technologies of system call sequences audit model based on machine learning and cooperative accident recovery.Under the condition of 100 M Data flow speed,the NSCDS software’s false negative is less than 6% and its false positive is less than 8%.Besides,all module functions work normally and the system can be used to carry out cooperative defense capability.
【Key words】 cooperative control; early-alert and orientation; security audit; accident recovery;
- 【文献出处】 西安交通大学学报 ,Journal of Xi’an Jiaotong University , 编辑部邮箱 ,2008年12期
- 【分类号】TP393.08
- 【被引频次】8
- 【下载频次】156