期刊文献+

扩展的基于STAT的网络安全监控系统

Extended STAT Based Network Security Monitoring
原文传递
导出
摘要 针对目前网络安全工具孤立使用,缺乏协调统一的网络安全监控机制的现状,论文提出了一个基于STAT的网络安全监控平台。它采用统一的事件格式,使用数据聚合技术减少冗余报警[1],多因素风险评估算法计算单事件的威胁,基于统计的风险评估算法评估网络安全态势,使管理者了解网络的安全状况及薄弱环节,进而及时采取有效的防护措施。 In the light that the network security devices all work alone and cack coordinated monitoring mechanism, this paper brings foreword "Extended STAT Based Network Security Monitoring" to manage all the devices together. A unified standard format is used to describe all the events. By data aggregation, the number of redundant alerts is reduced. In addition, the impact of a single event is evaluated by multiple factors and the network security evaluated by statistic based risk assessment technology. These help user find out the network situation and the weakness and thus take effective protective measures.
出处 《信息安全与通信保密》 2008年第3期55-57,61,共4页 Information Security and Communications Privacy
关键词 安全监控 状态转移 事件聚合 风险评估 network necurity monitoring STAT data fusion risk assessment
  • 相关文献

参考文献6

  • 1[1]Bass T.Intrusion Detection Systems and Multisensor Data Fusion[J].Communications of the ACM,2000,43(4)99~105.
  • 2[2]U CSB Reliable Software Group[EB/OL].http://www.cs.ucsb.edu/~seclab/projects/stat/index.html.
  • 3[3]Eckmann S T,Vigna G,Kemmerer R A.STATL:An Attack Language for State-Based Intrusion Detection[J].Computer Security,2002,10:1/2:71~104.
  • 4[4]Curry D,Debar H.Intrusion Detection Message Exchange Format:Extensible Markup Language(XML)Document Type Definition[J].draft-ietf-idwg-idmefxml-10.txt+,Jan.2003.
  • 5[5]Common Vulnerabilities and Exposures[EB/OL].http://www.cve.mitre.org/,2003.
  • 6[6]Valeur F,Vigna G,Kruegel C,et al.A comprehensive approach to Intrusion detection alert correlation[J].IEEE Trans.Dependable and Secure Computing,2004,1(3):146~169.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部