节点文献

基于异构系统的统一网络安全监控体系模型

Hybrid-System Based Integrated Network Security Supervision System Model

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 刘兰李之棠李家春梅成刚

【Author】 LIU Lan~(1,2),LI Zhi-tang~1,LI Jia-chun~3,MEI Cheng-gang~3 ~1(Department of Computer Architecture,Huazhong University of Science and Technology,Wuhan 430074,China) ~2(Department of Electronic Information,Guangdong Polytechnic Normal University,Guangzhou 510655,China) ~3(Department of Computer Science,South China University of Technology,Guangzhou 510641,China)

【机构】 华中科技大学计算机学院华南理工大学计算机科学与工程学院华南理工大学计算机科学与工程学院 湖北武汉430074广东技术师范学院电子系广东广州510655湖北武汉430074广东广州510641

【摘要】 针对大规模异构网络环境下安全行为的复杂性,现有的网络技术与管理缺少对海量原始数据的良好安全监控手段,本文提出构建统一的网络安全监控体系的思想,对各种异构数据源数据(审计日志和流量数据)进行标准化表示和整合,采用数据挖掘和小波分析的方法对数据进行分析处理,通过关联规则、流量规则和规则序列模式分析出整个网络的运行情况,对系统分析结果给出可视化结论,调整安全策略以适应网络安全动态性和整体性.

【Abstract】 In view of the complexity of network behavior among the hybrid systems,the technology and management of existing network systems are lack of enough effective security supervision measures for the great capability of the raw data.This paper developed a system model to supervise the security of network system,by normalizing and integrating the raw data from hybrid data-sources(including Syslog and traffic etc.),then using data-mining and wavelet technology to analyze the integrated information.At last this system used correlation rules,traffic rules and rule sequential pattern to analyze and drew out a visual conclusion of the network system security status which helps to adjust policy to enhance the system security.

【关键词】 网络行为学关联数据挖掘小波分析监测
【Key words】 network behaviorcorrelationminingwaveletsupervision
【基金】 国家网络与信息安全保障持续发展计划(2004研1-917-021)资助;国家重点基础研究发展计划“九七三”项目(2003CB314805)资助
  • 【文献出处】 小型微型计算机系统 ,Journal of Chinese Computer Systems , 编辑部邮箱 ,2006年09期
  • 【分类号】TP393.08
  • 【被引频次】15
  • 【下载频次】215
节点文献中: 

本文链接的文献网络图示:

本文的引文网络