期刊文献+

一种基于语言的事件流分析引擎的设计

Design and Implementation of a Language-Driven Event Stream Analysis Engine
下载PDF
导出
摘要 网络结构正在变得越来越复杂,对网络的监控需求也越来越强烈。本文首先分析了入侵检测中的各种规则描述语言以及基于语言的事件关联分析引擎,在此基础上设计了一种实用的事件描述语言用来表达复杂的事件模式以及多系统的事件流。并且基于该语言,实现了一个高效的事件流分析引擎,提出了一种复杂事件检测算法。 With the development and deepening of Enterprise Information,the problem of computer security is becoming increasingly outstanding. In this paper,we propose the event model and a new event description language to express composite event pattern,de-sign and realize a event stream analysis engine to monitor events from various systems.
作者 利业鞑
出处 《微计算机信息》 北大核心 2008年第12期263-264,252,共3页 Control & Automation
关键词 规则 事件关联 语言驱动 Rule Event Correlation Language-Driven
  • 相关文献

参考文献6

  • 1[1]Louis Perrochon,Eunhei Jang,Stephane Kasriel,David C.Luckham,Enlisting Event Patterns for Cyber Battlefield Awareness,
  • 2[2]Masoud Mansouri-Samaniyx and Morris Slomanzk,GEM:a generalized event monitoring language for distributed systems*,
  • 3[3]Dong Zhu,Adarshpal S.Sethi,SEL,A New Event Pattern Specification Language for Event Correlation
  • 4邓琦皓,吕晓斌,罗军勇.基于入侵行为模式的告警关联[J].微计算机信息,2005,21(10X):8-10. 被引量:6
  • 5[5]Isabelle Rouvellou,George W.Hart.Automatic Alarm Correlation for Fault Identification.Proceedings of the Fourteenth Annual Joint Conference of the IEEE Computer and Communication Societies.
  • 6[6]Cuppens and Miege 2002 CUPPENS,F.AND MIEGE,A.2002.Alert correlation in a cooperative intrusion detection framework[A].In:Proceedings of the 2002 IEEE Symposium on Security and Priva2 cy[C],2002.

二级参考文献2

  • 1A.Valdes and K.Skinner. probabilistic Alert Correlation [C]. In Fourth International Worshop on the Recent Advances in Itrusion Detection(RAID' 2001),Davis,USA,Oct 2001.
  • 2P.Ning, D.Reeves,and Yun Cui. Correlating Alerts Using Prerequisites of Intrusions. Technical Report TR-2001-13, North Carolina State University,Department of Computer Science, Dec 2001.

共引文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部