摘要
针对网络入侵检测中持续性攻击引发的多个报警事件时间间隔变化的问题,引入时间间隔变异系数描述报警的时间波动特征;通过将报警数据属性分为时间约束属性和相似度约束属性,提出了一种利用动态时间阈值约束的相似报警数据聚合方法。实验结果表明,这种方法能有效减少持续性攻击触发的冗余报警。
Focus on adjacent time intervals changing problem of alert sequences triggered by a persistent attack in NIDS,this article proposes to describe time fluctuation character of alerts with a time variation coefficient and an alert aggregation method based on dynamic time threshold by which alert data are divided into temporal constraint feature and similarity constraint features.Experiment results show that redundancy alerts triggered by persistent attack can be decreased effectively.
出处
《沈阳航空工业学院学报》
2010年第5期68-72,共5页
Journal of Shenyang Institute of Aeronautical Engineering
关键词
入侵检测
报警聚合
时间间隔阈值
属性相似度
intrusion detection
alert aggregation
time interval threshold
attribute similarity