摘要
针对当前防火墙存在的安全问题,分析并比较现有防火墙安全测评方法,提出了一种基于日志挖掘的防火墙安全测评方法。基于现有标准和实际安全需求,提取防火墙安全测评指标体系,并采用相应的日志挖掘算法,发掘出关联数据,再利用测评分析算法,分析防火墙的安全策略是否符合相应指标要求,为其安全整改提供参考建议。该方法借鉴了数据挖掘的思想,审计日志分析也能够真实反映防火墙的安全问题,同时通过改造决策树算法,优化了安全测评的效率。实验结果表明,提出的测评方法能够有效分析防火墙的配置策略问题。
To detect and solve security problems of the firewalls, several existing methods of security evaluation on firewall are compared and a new way based on its audit log is proposed, which uses the idea of data mining. Firstly, the firewall evaluation index system is generated from the related standards and the security requirements. Secondly, log mining algorithms are used for extracting associated information. Then, the mined information is imported into the corresponding evaluation algorithms for analyzing and the results can help strengthen the firewall security. This method use the idea of data mining and the evaluation results could reflect the firewall problems veritably. It also optimizes some algorithms to enhance the efficiency. Finally, experiments show that the proposed method analyzes the security problems of the online firewalls effectively.
出处
《计算机工程与设计》
CSCD
北大核心
2012年第1期66-73,共8页
Computer Engineering and Design
基金
国家863高技术研究发展计划基金项目(2009AA01Z439)
国家高技术产业化项目信息安全专项基金项目
信息网络安全公安部重点实验室开放基金项目(C10606)
关键词
审计日志
数据挖掘
规则匹配
决策树
测评指标体系
安全测评
audit log; data mining; rules matching; decision tree; evaluation index system; security evaluation