摘要
网络安全产品之间由于缺乏数据信息交换机制,导致了各自的安全信息不能彼此共享;同时为了解决网络上大量的报警和误报,这就需要找出网络检测数据深层次关系,并高效地检测已知、未知的攻击,由此提出了网络安全的信息管理与分析系统,同时给出了事件聚合、关联分析方法,提取关联规则,达到进一步聚合安全事件,从而达到全面分析的目的。
Because of the lack of data exchange mechanism, security product can't sharing the security information each other. In order to resolve the large volume of alarm message or false alarm, discovery the immanent relationship in detected data and effectively detect diversified attack, a network security management and analysis system is put forward, simultaneously, analytical method of data fusion and data association is discussed and the security event information can be gathered, all what are taken to achieve the all-around analysis about security information.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第19期4625-4627,共3页
Computer Engineering and Design
基金
教育部"新世纪优秀人才支持计划"基金项目(NCET-04-0843)
关键词
网络安全
入侵检测
关联分析
聚类分析
概化
network security
intrusion detection
association analysis
cluster analysis
generalization