节点文献

多源安全数据可视化关键技术研究与实现

Studies And Implementations of Key Technologies of Multi-source Security Data Visualization

【作者】 张瑜

【导师】 向宏;

【作者基本信息】 重庆大学 , 软件工程, 2015, 硕士

【摘要】 网络安全技术与数据可视化的结合形成了网络安全可视化这一新的研究方向。在处理海量信息时利用网络安全可视化能够有效地解决传统分析方法所面临的认知负担过重,交互性不强等一系列问题,并且更好地发挥可视分析技术的作用,利用多传感器的有效协作,建立多源日志数据协同分析的基础,以展示出多源日志信息间的联系,帮助用户高效的识别异常事件和攻击特征发展趋势,并进一步全面的掌握网络安全状态。本文根据信息可视化参考模型,利用数据的特征融合对多源安全日志数据进行分析处理,然后将处理后包含有时间、安全事件类型、源IP、目的IP等有用的多源日志记录信息作为可视化输入,通过改进后的雷达图及网络拓扑图算法将以上信息展示在安全分析人员面前,帮助他们:①查看某一时间段内发生某一类安全事件的所有设备;②统计某设备在不同时间段内发生的所有安全事件,找到可能存在漏洞的设备以及有可疑行为的IP地址;③突出显示出发生了这些安全事件的设备以及发生的路径,帮助安全分析人员找到需要重点关注的关键节点或关键节点的集合。在网络安全可视化关键技术研究的基础上,本文对多源安全日志可视化进行了设计实现,并选取了由VAST challenge 2013提供的Netflow日志、防火墙日志以及主机监控Bigbrother日志等有关国际标准数据集作为实验数据对可视化的进行了验证,证明了其有效性。

【Abstract】 Network security visualization is a new research field which consists of network security and data visualization technology. This technology can effectively solve a series of problems such as heavy cognitive burden and less interaction when traditional methods deal with vast amounts of information, and play an efficient role in visualization technology, which makes use of effective collaboration of multiple sensors to build the basis of collaborative analysis of multi-source log data and display the relationship between them in order to help security analysts efficiently identify anomalous events and trend of attack features as well as fully master network security situation.On the basis of reference model for visualization, this thesis analyze and process multi-source log data though feature fusion, then take the log information includes time, types of security events, source IP and destination IP as the input of visualization, and display them though modified algorithms of radar and network topology, that help analysts:① Check all devices occurred a certain type of security event in a certain period time;② Count all security events of one certain device in a period time to find the device which may have suspicious behaviors;③ Highlight the devices and trends that security events happened to help analysts find critical nodes and the collection of them.Based on the theory of network security visualization, this paper designs and implement multi-source security logs, and takes the national standard data sets such as firewall logs, Netflow logs and Bigbrither logs provided by VAST challenge 2013 as the experimental data to verify the effectiveness of this visualization technology.

  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2016年 06期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络