摘要
协同和分布式的网络攻击对传统的网络安全防护提出了巨大的挑战,同时也对分布式入侵检测技术提出了更高的要求,而有效融合多种入侵检测系统报警信息能够提高告警的准确性。首先给出了五维度报警信息关联的定义;然后设计与实现了带有实时响应机制的层次化关联模型,该模型具有较广泛的适用性,每一层都可以作为一个单独的模块完成相应的功能;最后给出了报警信息融合模块的实现。实验证明:报警信息融合可以降低误报、漏报率,并能识别攻击意图,达到预警的目的。
Conventional network security protection is facing a great challenge of coordinated and distributed attack, so distributed intrusion detection technology is required. Fusing multi-kinds of IDS alerts can effectively improve warning veracity. Based on annotation to alert correlation definition renewedly, the paper designed and implemented layered correlation model with real-time response mechanism. The model is much adaptive, each layer of which can do its work independently. At last, the function of fusing alert information is implemented, which can resolve problems of management of alerts, false negative and false positive better and can warn according to attack intention identified.
出处
《计算机应用研究》
CSCD
北大核心
2006年第3期98-101,104,共5页
Application Research of Computers
基金
国家"863"计划资助项目(2003AA142010)
关键词
入侵检测
报警关联
响应
信息融合
Intrusion Detection
Alert Correlation
Response
Information Fusion