节点文献

安全事件关联分析引擎的研究与设计

Research and Design of Correlation Analysis Engine for Security Incident

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 熊云艳毛宜军丁志

【Author】 XIONG Yunyan1,2,MAO Yijun2,3,DING Zhi3,4(1.Department of Computer,Guangdong Vocational College of Industry,Guangzhou 510510;2.College of Computer Science & Engineering,South China University of Technology,Guangzhou 510640;3.College of Information,South China Agricultural University,Guangzhou 510640;4.Center of Examination in Guangdong Province,Guangzhou 510641)

【机构】 广东工贸职业技术学院计算机系华南理工大学计算机科学与工程学院华南农业大学信息学院 广州510510广州510640华南农业大学信息学院广东省考试中心广州510641

【摘要】 入侵检测系统是动态安全防御里的重要环节,现有的入侵检测系统(IDS)存在一个致命的缺陷:误报率高居不下,IDS无法展现事件之间的逻辑关系,结果用户很难了解事件背后隐藏的攻击策略或逻辑步骤。为了解决IDS存在的上述问题,在深入分析入侵技术的基础上提出了基于入侵序列的启发式关联方法,设计并实现了一个事件关联分析引擎,最后验证了有效性。

【Abstract】 Intrusion detection system is one of the dynamic defensive techniques,but current intrusion detection systems(IDSs) usually generate a large amount of false alerts and none of them can capture the logical steps or strategies behind the attacks.As a result,it is difficult for human users to understand the intrusions behind the alerts and take appropriate actions.This paper presents a correlation analysis approach based on the sequences and heuristic arithmetic to address these issues after analyzing large numbers of attack techniques and designs a correlation analysis engine for security incident and conducts one experiment to demonstrate the potential of the system,in reducing false alerts and uncovering attack strategies.

  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2006年13期
  • 【分类号】TP393.08
  • 【被引频次】14
  • 【下载频次】235
节点文献中: 

本文链接的文献网络图示:

本文的引文网络