首页 | 本学科首页   官方微博 | 高级检索  
     

安全报警事件关联算法研究
引用本文:郭山清,阳雪林,曾英佩,谢立,高丛.安全报警事件关联算法研究[J].计算机应用,2005,25(10):2276-2279.
作者姓名:郭山清  阳雪林  曾英佩  谢立  高丛
作者单位:1.南京大学软件新技术国家重点实验室; 2.江苏南大苏富特公司研究院; 3.奥克兰大学计算机系 江苏南京210093; 4.南京大学计算机科学与技术系
基金项目:国家863计划项目(2003AA142010);国家自然科学基金资助项目(60373064)
摘    要:已经获得广泛应用的防火墙、IDS、防病毒软件等安全设备在运行过程中会产生大量独立的、原始的报警信息,这些报警信息除了具有海量的特点外,还有比较高的误报率和漏报率,导致用户难于对攻击及时做出响应。利用关联分析的方法对海量报警事件进行分析并提取攻击场景是解决此问题的基本手段。通过简单的分类综述了安全领域中报警事件关联算法的研究现状,并指出了需要进一步研究的问题。

关 键 词:安全管理    报警事件关联    入侵检测
文章编号:1001-9081(2005)10-2276-04
收稿时间:2005-04-20
修稿时间:2005-04-202005-07-08

Survey of the security alerts correlation algorithms
GUO Shan-qing,YANG Xue-lin,ZENG Ying-pei,XIE Li,GAO Cong.Survey of the security alerts correlation algorithms[J].journal of Computer Applications,2005,25(10):2276-2279.
Authors:GUO Shan-qing  YANG Xue-lin  ZENG Ying-pei  XIE Li  GAO Cong
Affiliation:1.State Key Laboratory for Novel Software Technology,Nanjing University,Nanjing Jiangsu 210093,China;2.Department of Computer Science and Technology,Nanjing University,Nanjing Jiangsu 210093,China;3.Department of Computer Science,University of Auckland,Auckland 1020,New Zealand;4.Research Center of Nandasoft Corporation,Nanjing Jiangsu 210008,China
Abstract:security devices(e.g.firewalls,IDS's,anti-virus tools etc) that have been widely adopted in enterprise environments may generate huge amounts of independent,raw attack alerts,which are characterized by high false positive ratio and false negative ratio.As a result,it is difficult for users to understand these alerts and respond correspondingly.Therefore,handling the huge number of alerts produced by security devices is becoming a critical and challenging task in network security research.A general approach for solving this problem is to do some correlation analysis with these alerts and build attack scenario.A general survey of the contemporary alerts correlation algorithms was given in this paper by a straight forward classification paradigm,and some problems for future research were addressed.
Keywords:security management  alert correlation  intrusion detection
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号