期刊文献+

基于模式匹配的告警关联 被引量:4

Alerts Correlation Based on Intrusion Action Pattern
下载PDF
导出
摘要 告警关联技术是入侵检测领域中一个新的发展方向,它对解决目前入侵检测系统存在的告警数量大、告警信息含量少、虚警数量大等问题具有十分重要的意义。文章介绍了在我们设计开发的分布式协同入侵检测系统(DACIDS)中通过对入侵行为模式的匹配而进行告警关联的方法。入侵行为模式是定义在时间基础上的一组谓词公式,其实质是通过时间限制联系在一起的入侵事件的集合。该方法在对大量告警进行关联的同时,对虚警的处理尤为有效。 The technology of alerts correlation is a new trend for intrusion detection. It is very useful to solve problems, such as alarm overload, poorness of the alarms semantics and false negatives, in current intrusion detection system. In this paper, we propose to use intrusion action pattern to correlate alerts in our Distributed Active Collaboration Intrusion Detection System (DACIDS). Intrusion action pattern are sets of propositions related on times. In other words, it' s a set of events, linked together by time constraints. Our method has been proved to address the problems coneemed.
出处 《微电子学与计算机》 CSCD 北大核心 2005年第7期103-106,共4页 Microelectronics & Computer
关键词 入侵检测 告警关联 入侵行为模式 Intrusion Detection System (IDS), Alert correlation, Intrusion Action Pattern (IAP)
  • 相关文献

参考文献5

  • 1A Valdes, K Skinner. Probabilistic Alert Correlation[C]. In Fourth International Worshop on the Recent Advances in Itrusion Detection (RAIDY'2001), USA, Oct 2001.
  • 2P Ning, D Reeves, Yun Cui. Correlating Alerts Using Prerequisites of Intrusions. Technical Report TR-2001-13,North Carolina State University, Department of Computer Science, Dec 2001.
  • 3Qihao Deng, Qingxian Wang, Jingeng Guo. The Research and Implementation of Distributed Active and Cooperative Intrusion Detection System. Proceedings of the 2nd International Conference on Security and Protection of Information, Brno, Czech Republic, April, 2003.
  • 4Y Shoham. Temporal Logics in AI : Semantical and Ontological Considerations,Journal of Arti_cial Intelligence,1987: 89-104.
  • 5C Dousson. Extending and Unifying Chronicles Representation with Event Counters.In Proceedings of the 15th European Conference on Arti_cial Intelligence (ECAI 2002),August 2002.

同被引文献27

引证文献4

二级引证文献16

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部