期刊文献+

入侵检测报警关联技术 被引量:1

Intrusion Detection Alert Correlation Techniques
下载PDF
导出
摘要 报警关联技术分析不同安全产品产生的报警,从中识别出真正有意义的攻击警报,并减少大量的误报警,降低安全管理员的工作量。该文介绍了报警关联的基本模型和主要技术,分析了主要的关联方法,探讨了报警关联技术的发展方向。这些讨论对应用或发展报警关联技术都有参考价值。 Many intrusion detection technologies are complementary to each other. The alert correlation technology analyzes alerts generated from different security products, so that false alerts are greatly reduced, real attacks are more easily discerned, accordingly, the work load on system administrators is largely released. Herein, basic models and technologies of alert correlation are discussed. Important correlation algorithms are analyzed; and development tendencies of alert correlation technologies are also predicted.
作者 姜兆元 赵军
出处 《计算机工程》 CAS CSCD 北大核心 2007年第17期173-175,共3页 Computer Engineering
基金 重庆自然科学基金(9111) 重庆市教委科学技术研究项目(040509) 重庆自然科学基金资助重点项目(2005BA2003)
关键词 入侵检测 报警关联 网络安全 intrusion detection alert correlation network security
  • 相关文献

参考文献14

  • 1IETF Intrusion Detection Exchange Format Working Group.The Intrusion Detection Message Exchange Format[EB/OL].Internet Draft.(2004-07-08).http://xml.coverpages.org/draft-ietf-idwg-idmef-xml-12.txt.
  • 2Mu C.Intrusion Detection Alert Verification Based on Multilevel Fuzzy Comprehensive Evaluation[C]//Proc.of 2005 International Conference on Computational Intelligence and Security.Berlin:Springer-Verlag,2005:9-16.
  • 3Krugel C,Toth T.Decentralized Event Correlation for Intrusion Detection[C]//Proc.of the 4th International Conference on Information Security and Cryptology.2001.
  • 4Cuppens F.Alert Correlation in a Cooperative Intrusion Detection Framework[C]//Proc.of IEEE Symposium on Security and Privacy.2002.
  • 5Ning P,Cui Y.Analyzing Intensive Intrusion Alerts via Correlation[C] //Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection,Zurich,Switzerland.2002.
  • 6Yu D,Frincke D.A Novel Framework for Alert Correlation and Understanding[C]//Proc.of International Conference on Applied Cryptography and Network Security.2004:452-466.
  • 7Ning P.Building Attack Scenarios Through Integration of Comple-mentary Alert Correlation Methods[C]//Proc.of the 11th Annual Network and Distributed System Security Symposium.2004-02.
  • 8Debar H,Wespi A.Aggregation and Correlation of Intrusion-detection Alerts[C]//Proc.of Conference on Recent Advances in Intrusion Detection.2001:85-103.
  • 9Yu D.Improving the Quality of Alerts and Predicting Intruder's Next Goal with Hidden Colored Petri-Net[EB/OL].(2006-05).http:// research.microsoft.com/~dongyu/.
  • 10Valdes A,Skinner K.Probabilistic Alert Correlation[C]//Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection.2002:54-68.

同被引文献4

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部