摘要
针对大规模网络安全监控需求,采用"分布式获取,分域式处理"的思想研究基于多传感的网络安全态势感知系统框架结构,并在此基础上给出系统的环形物理结构和层次概念模型;该框架结构自下而上依次分为"信息获取层-要素提取层-势决策层"3个层次,对每个层次所涉及的模块进行详细设计,并给出多源异构安全信息XML格式化的解决方案。该结构是一个开放、可扩展的环形结构,能有效地降低系统实现复杂性,避免单点失效问题。此外,还从整体上明确了层次与层次、组件与组件的关系,以指导工程实践和关键技术的进一步开展。
Combined with the large-scale network security monitor application requirements,network security situation awareness system(NSSAS) architecture based on multi-sensors was studied with using the idea of 'distributed acquisition,multi-domain processing',and then the corresponding ring physical architecture and hierarchical conceptual model of NSSAS were put forward.The architecture of NSSAS is composed of three levels,including information acquisition level,element extraction level and situation decision-making level from bottom to top successively.The modules of every level were designed in detail,and the solution of multi-source heterogeneous security information XML format was given.The NSSAS architecture based on multi-sensors is an open and extensible ring architecture that can reduce system implementation complexity and avoid single-point failure problem.At the same time,it can clearly describe the relationship among levels and components,and guide the development of engineering practice and key technologies.
出处
《计算机科学》
CSCD
北大核心
2011年第3期144-149,158,共7页
Computer Science
基金
国家863计划(2007AA01Z401)
国家自然科学基金(90718003
60973126)
省部共建河南大学科研项目(SBGJ090602)资助
关键词
网络安全
态势感知
异构传感器
体系结构
Network security
Situation awareness
Heterogeneous sensors
Architecture