摘要
针对目前网络安全工具孤立使用,缺乏协调统一的网络安全监控机制的现状,论文提出了一个基于STAT的网络安全监控平台。它采用统一的事件格式,使用数据聚合技术减少冗余报警[1],多因素风险评估算法计算单事件的威胁,基于统计的风险评估算法评估网络安全态势,使管理者了解网络的安全状况及薄弱环节,进而及时采取有效的防护措施。
In the light that the network security devices all work alone and cack coordinated monitoring mechanism, this paper brings foreword "Extended STAT Based Network Security Monitoring" to manage all the devices together. A unified standard format is used to describe all the events. By data aggregation, the number of redundant alerts is reduced. In addition, the impact of a single event is evaluated by multiple factors and the network security evaluated by statistic based risk assessment technology. These help user find out the network situation and the weakness and thus take effective protective measures.
出处
《信息安全与通信保密》
2008年第3期55-57,61,共4页
Information Security and Communications Privacy
关键词
安全监控
状态转移
事件聚合
风险评估
network necurity monitoring
STAT
data fusion
risk assessment