期刊文献+

基于日志审计与性能修正算法的网络安全态势评估模型 被引量:97

A Network Security Situational Awareness Model Based on Log Audit and Performance Correction
下载PDF
导出
摘要 文章分析和比较了目前的安全态势评估方法,提出了一种基于日志审计与性能修正算法的网络安全态势评估模型.首先利用日志审计评估节点理论安全威胁,并通过性能修正算法计算节点安全态势.然后利用节点服务信息计算网络安全态势,并且采用多种预测模型对网络安全态势进行预测,绘制安全态势曲线图.最后构建了一个网络实例,使用网络仿真软件对文中提出的态势评估模型和算法进行了验证.实验证明该方法切实有效,比传统方法更准确地反映了网络的安全态势和发展趋势. This paper analyzes and compares the existing situational awareness methods and proposes a network security situational awareness model based on log audit and performance correction algorithm. First, nodes theoretic security threat is got by log audit and the value of nodes security situation is computed by performance correction algorithm. Then the value of network security situation is computed using service information, the future threat is predicted by several prediction models, and the Security Situational Graph (SSG) is drawn. Finally an example is given to validate the network security situational awareness model and algorithm by simulation software. The example proves that the model is more effective and accurate to reflect the network security situational and its trends than traditional methods.
作者 韦勇 连一峰
出处 《计算机学报》 EI CSCD 北大核心 2009年第4期763-772,共10页 Chinese Journal of Computers
基金 国家"八六三"高技术研究发展计划项目基金(2006AA01Z437 2007AA01Z475 2006AA01Z412 2006AA01Z433)资助~~
关键词 安全态势评估 日志审计 性能修正 安全态势曲线图 预测 security situational awareness log audit performance correction security situational graph predict
  • 相关文献

参考文献10

  • 1Lau S. The spinning cube of potential doom. Communications of the ACM, 2004, 47(6): 25-26
  • 2Lakkaraju K, Yurcik W, Lee A J. NVisionlP: Netflow visualizations of system state for security situational awareness// Proceedings of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security. Washington DC, 2004: 65-72
  • 3Yin X, Yurcik W, Treaster M. VisFlowConnect: Netflow visualizations of link relationships for security situational awareness//Proceedings of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security. Washington DC, 2004:26-34
  • 4Bass T. Intrusion detection systems & multisensor data fusion: Creating cyberspace situational awareness. Communications of the ACM, 2000, 43(4): 99-105
  • 5D' Ambrosio B. Security situation assessment and response evaluation (SSARE)//Proceedings of the DARPA Informa- tion Survivability Conference & Exposition Ⅱ. Anaheim, 2001 : 387-394
  • 6Yegneswaran V, Barford P, Paxson V. Using honeynets for internet situational awareness//Proceedings of the 4th Workshop on Hot Topics in Networks. Maryland, 2005
  • 7陈秀真,郑庆华,管晓宏,林晨光.层次化网络安全威胁态势量化评估方法[J].软件学报,2006,17(4):885-897. 被引量:341
  • 8George E P B, Gwilym M J. Time Series Analysis: Forecasting and Control. San Francisco: Holden Day Inc. , 1976
  • 9童明荣,薛恒新,林琳.基于Holt-Winter模型的铁路货运量预测研究[J].铁道运输与经济,2007,29(1):79-81. 被引量:10
  • 10Fall K, Varadhan K. The ns manual (formerly ns notes and documentation). California: UC Berkeley, LBL, USC/ISI, and Xerox PARC, 2007

二级参考文献4

共引文献349

同被引文献633

引证文献97

二级引证文献844

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部