摘要
网络应用规模不断壮大,随之而来的是网络安全不断遭受威胁,入侵检测系统应运而生。但是大量低级报警、误报、漏报等问题严重影响了IDS的性能,为了解决IDS面临的诸多问题,亟需对安全事件进行关联分析。
With the increasing application of network and the expanding scale of network, endless attacks on network security are causing a wide concern. Although the Intrusion Detection System(IDS) is a system that serves the purpose of network protection, problems still remain, such as alert flooding, false positives, false negatives, and so on. Therefore, it is necessary to make analyses of various alerts and their correlation.
基金
义乌市科技局项目资助(09-1-30)
关键词
事件关联
数据融合
入侵检测
网络安全
alert correlation
data fusion
intrusion detection
network security