期刊文献+

入侵报警聚合关联模型的研究与实现

下载PDF
导出
摘要 入侵报警聚合关联模型是一个快速、有效的报警分析架构。它通过将低级报警事件与主机脆弱性信息进行聚合、高级报警事件之间进行基于知识库的关联和增加新的功能组件,降低入侵报警的误报率,提高报警的解读性。
出处 《计算机应用》 CSCD 北大核心 2007年第B12期141-143,共3页 journal of Computer Applications
  • 相关文献

参考文献6

  • 1VALDES A, SKINNER K. Probabilistic alert correlation[ C]//Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection, LNCS2212. Berlin: Springer-Verlag, 2001:54 -68.
  • 2GEIB C, GOLDMAN R. Plan recognition in intrusion detection system[ C]// DARPA Information Survivability Conference and Exposition Ⅱ( DISCEX Ⅱ). Los Alamitos: IEEE Computer Society, 2001: 46 -55.
  • 3NING PENG, CUI YUN. An intrusion alert correlator based on prerequisites of intrusions, TR-2002-01 [ R]. North Carolina State University, Department of Computer Science, 2002.
  • 4CUPPENS F, MIEGE A. Alert correlation in a cooperative intrusion detection frame-work[ C]//Proceedings of the 2002 IEEE Symposium on Security and Privacy. Washington: IEEE Computer Society Press, 2002:202 -215.
  • 5LEE S J, CHUNG B C, KIM H Y, et al. Real-time analysis of intrusion detection alerts via correlation[ J]. Computers & Security, 2006, 25(3): 169 - 183.
  • 6MIT Lincoln Lab. 2000 DARPA intrusion detection scenario specific datasets[EB/OL]. [ 2007 -05 -10]. http://www. 11. mit. edu/ IST/ideval/data/2000/2000_data_index. html.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部