期刊文献+

基于OSSIM关联分析技术的蠕虫攻击检测

Worm Detect in Basic of OSSIM’s Correlatoin Analysis Technic
下载PDF
导出
摘要 由于近些年蠕虫攻击日益泛滥和业界相应安全检测产品的功能单一化,导致了安全事件频繁虚警和漏警。鉴于目前这种困境,该文在分别研究了著名开源项目OSSIM和蠕虫攻击技术的基础上,提出了基于序列化启发式关联技术的蠕虫检测方法。该文中提出的这种关联方法采用XML文档描述蠕虫入侵模式,这就使该关联方法比其他方法更加灵活、可信。最后,该文中不仅给出了蠕虫检测的通用关联规则,还搭建了以OSSIM为母体的安全管理平台进行测试。从测试过程和结果显示了该方法的灵活可靠性。 R, ecently, due to worm attack activity and security products simplify, consequently there are much more negative and over-looked alerts. Accordingly, this paper created a method which was basic of heuristic correlatoin ananlysis technic by doing some researches of famous open source progeram named OSSIM and the characters of worm attack. The method in this paper was agility and reliable because of being implemented by XML documentnot. At the end, this paper not only gave currency rules of detecting worm attack, but also did tests after building security management system in basic of OSSIM.Through the result of the test,it was found that this method was agility and reliable.
作者 张萍 山岚
出处 《计算机安全》 2008年第9期58-60,共3页 Network & Computer Security
关键词 OSSIM 入侵检测 蠕虫 关联规则 OSSIM intrude detection worm correlation rule
  • 相关文献

参考文献1

二级参考文献7

  • 1中国互联网络信息中心.中国互联网络发展状况统计报告[EB/OL].http://www.cnnic.net.cn,2004—07—21/2004—08—09.
  • 2Richardson R.2003 CSI/FBI Computer Crime and Security Survey[R/OL].http://www.gocsi.com/awareness/fbi.jhtml,2003.
  • 3Joel S,Stuart M,George K.黑客大曝光[M].北京:清华大学出版社,2002.
  • 4Valdes A,Skinner K.Probabilistic Alert Correlation[C].Proceedings of Recent Advances in Intrusion Detection.Berlin Heidelberg:Springer-Verlag,2001:45-55.
  • 5Julisch K.Mining Alarm Clusters to Improve Alarm Handling Efficiency[C].Proceedings of the 17th Annual Computer Security Applications Conference,New Orleans,Louisiana,USA,2001.
  • 6Manganaris S,Christensen M,Zerkle D.A Data Mining Analysis of RTID Alarms[J].Computer Networks,2000,34(4):571-577.
  • 7Debar H,Wespi A.Aggregation and Correlation of Intrusion Detection Alerts[C].Proceedings of Recent Advances in Intrusion Detection.Berlin Heidelberg:Springer-Verlag,2001:93-108.

共引文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部