期刊文献+

基于多源事件融合的分布式SOC技术体系 被引量:1

Distributed SOC Technology System based on Multi-Source Events Fusion
原文传递
导出
摘要 安全运营中心(SOC)作为运营方的安全核心,对整个业务网络的安全运营起着关键作用。鉴于目前国内已有SOC产品的局限性,论文提出了一种基于网络事件流的SOC产品解决方案。该方案通过相互协作的分布式安全部件从杂乱无章的海量运营事件中挖掘出安全事件,经汇聚以及关联分析后,评估其对信息资产CIA的已有(或将有)影响度,并依据安全策略标准自动启动安全域与业务域安全部件协同,积极防御。 As the security core, Security Operation Center(SOC) is very important for the security operation of business network, In this paper, a new solution based on network event flows is proposed for overcoming the limitation exist in SOC product. Its idea is that mining security events from a large numbers of operation events by cooperative distributed security components, make effect evaluation to the CIA of information assets, then, realize automatically the cooperate between security domain and business domain according to security policy standard.
出处 《信息安全与通信保密》 2008年第4期67-70,共4页 Information Security and Communications Privacy
关键词 SOC(Security Operation Center) 安全事件 免疫知识库 安全协同 SOC(Security Operation Center) security event immunity knowledge base security cooperate
  • 相关文献

参考文献3

二级参考文献7

  • 1J. Allen, A. Christie, A. Fithen, et al. State of the practice of intrusion detection technologies. Software Engineering Institute,Carnegie Mellon University, Tech. Rep. : CMU/SE1-99-TR028, 2000.
  • 2S. Staniford, J. A, Hoaglond, J, M, McAlerney. Practical automated detection of stealthy portscans, The 7th ACM Conf.Computer and Communications Security, Athens, Greece, 2000.
  • 3Fyodor. The art of port scanning, http://www.insecure.org/nmap/nmap-doe. html, 2004
  • 4L. Heberlein, G.Dias, K. Levitt, et al. A network security monitor. IEEE Symposium on Research in Security and Privacy,Oakland, CA, 1990.
  • 5Steven Cheung, Rick Crawford, Mark Dilger, et al, The design of GrIDS: A graph-based intrusion detection system. U. C,. Davis Computer Science Department, Tech. Rep. : CSE-99-2, 1999.
  • 6Martin Roesch. snort, http://www.snort.org/, 2004.
  • 7P. Porras, A. Valdes. Live traffic analysis of TCP/IP gateways.1998 lnternet Society Symposium on Network and Distributed System Security, San Diego, 1998.

共引文献8

同被引文献7

引证文献1

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部