期刊文献+

基于Drools的离线分析研究与实现

Off-line Analysis Research and Implementation Based on Drools
下载PDF
导出
摘要 提出了一种基于Drools离线分析的方法,是对主机监控系统实时分析无法深入的一种补充。对监控系统产生的海量警报信息进行压缩,对攻击事件的发生过程进行安全事件关联分析。首先介绍了Drools的工作原理,然后基于系统整体模型,给出了规则推理的详细设计策略和关键技术的实现。最后进行了离线分析仿真试验,U盘监控类离线分析结果表明警报信息数量的压缩率在9.898%以上并得到了攻击(操作)过程。 A kind of offline analysis based on Drools was proposed, h was a complementarily to real-time analysis of the host detection system. It not only compressed the large quantity of alerts generated by monitoring system, but also accomplished the security events association on the whole operation procedure. Firstly, general model was construeted based on the Drools principle. Secondly, the detailed design tactics and the key technologies realization were provided. Finally the off-line simulation results using the flash memory disks alerts showed that the quantity compressibility of alerts was above 9.898% and the attack (operation) procedure was successfully achieved.
出处 《微计算机信息》 2009年第3期148-149,134,共3页 Control & Automation
关键词 主机监控系统 离线分析 安全事件关联 DROOLS host detection system off-line analysis security events association Drools
  • 相关文献

参考文献5

二级参考文献24

  • 1邓琦皓,吕晓斌,罗军勇.基于入侵行为模式的告警关联[J].微计算机信息,2005,21(10X):8-10. 被引量:6
  • 2[1]Poirk Y. Event Correlation. IEEE Potentials, 2001,20(2): 34~35 被引量:1
  • 3[2]Ye Nong, Li Xiaoyang, Chen Qiang, et al. Probabilistic techniques for intrusion detection based on computes audit data. IEEE Transactions on System, Man, and Cybernetics, 2001, 31(4): 266~274 被引量:1
  • 4DENNING D. Intrusion-Detection model[J]. IEEE Trans on Software Engineering, 1987, 13(2). 被引量:1
  • 5JULISCH K. Clustering Intrusion Detection Alarms to Support Root Cause Analysis[ J]. in ACM Transactions on Information and System Security 6(4), 2003.9. 被引量:1
  • 6Cuppens and Miege 2002 CUPPENS, F. AND MIEGE, A. 2002.Alert correlation in a cooperative intrusion detection framework[ A].In: Proceedings of the 2002 IEEE Symposium on Security and Privacy[ C], 2002. 被引量:1
  • 7HAtALA A, SARS C, RONJA A-M, et al. Event Data Exchange and Intrusion Alert Correlation in Heterogeneous Networks[ A]. In:Proceedings from the Eight Colloquium for Information Systems Security Education. Printing House[C], 2004. 84-91. 被引量:1
  • 8CUPPENS F, LAMBDA OR. A language to model a database for detection of attacks[ A]. In: Proc. of Recent Advances in Intrusion Detection ( RAID 2000) [C], 2000. 197 -216. 被引量:1
  • 9KRUGEL C, TOTH T, KERER C. Decentralized Event Correlation for Intrusion Detection[Z]. 4th International Conference on Information Security and Gryptology (ICISC), 2001. 被引量:1
  • 10NING P, CUI Y, REEVES DS. Analyzing intensive intrusion alerts via correlation[ A]. In: Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection[ C]. Zurich, Switzerland, 2002. 被引量:1

共引文献28

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部