期刊文献+

一种基于流立方体的网络安全态势感知模型 被引量:1

A Network Security Situation Awareness Model Based on Stream Cube
下载PDF
导出
摘要 网络安全态势感知是网络安全监控技术一个新的发展方向,对网络安全态势的掌握对于网络安全而言具有重要的意义。在已有的关于数据立方体模型的研究基础之上,本文提出了一种基于流立方体模型的网络安全态势感知模型,以描述和抽象化网络安全态势感知中涉及的多维分析结构,从网络安全事件统计数据流的数据特征出发分析网络安全态势。给出了基于频率、趋势和熵值这三种数据特征的模型实例,利用流立方体相邻层次间单元的关系证明了这三种数据特征可以只从原始数据计算底层单元的特征,而上层单元的数据特征则可以通过对底层数据特征的运算而直接得到,从而实现高效计算。实际应用系统的构建和利用网络安全数据的测试实验表明了所提模型和方法的有效性。 Network security situation awareness is a new trend of network security monitoring technology.The awareness of the situation is very important to network security.Based on the existing research about data cube,we propose a network security situation awareness model to describe and abstract the multi-dimensional analysis structure related to the network security situation awareness.We can analyze the network security situation from the aspect of the network security events' statistical characteristics based on this model and give an instance of the model based on frequency,trend and entropy characteristics.Then we improve the efficiency of the method by studying the correlation of the cells among the neighboring levels in the data cube on the basis of keeping the accuracy of the results.We also prove that we only need to get the lowest level cube's characteristics from the raw data,and get the higher level cube's characteristics by an indirect way.Building the practical applications and extensive experiments based on the real network security dataset demonstrates the effectiveness of the proposed model and methods.
出处 《计算机工程与科学》 CSCD 北大核心 2011年第8期8-13,共6页 Computer Engineering & Science
关键词 信息安全 网络安全态势感知 数据立方体 数据流 information security network security situation awareness data cube data stream
  • 相关文献

参考文献9

  • 1Endsley M R.Situation Awareness in Aviation Systems[M]∥Garland D J,Wise J A,Hopkin V D,eds.Handbook of Aviation Human Factors.Mahwah,NJ: Lawrence Erlbaum,1999:257-276.
  • 2Steinberg A N,Bowman C L,White F E.Revisions to the JDL Data Fusion Model[C]∥Proc of SPIE AeroSense,1999:430-441.
  • 3Endsley M R.Toward a Theory of Situation Awareness in Dynamic Systems[J].Human Factors,1995,37(1):32-64.
  • 4Bass T,Gruber D.A Glimpse into the Future of ID[EB/OL].[1999-08-10].http://www.usenix.org/publications/login/199929/features/future.htm.
  • 5Shifflet J.A Technique Independent Fusion Model for Network Intrusion Detection[C]∥Proc of the Midstates Conf on Undergraduate Research in Computer Science and Mathematics,2004:13-19.
  • 6Gates C,Collins M,Duggan M,et al.More Netflow Tools for Performance and Security[C]∥Proc of the 18th USENIX Conf on System Administration,2004:121-132.
  • 7Lakkaraju K,Yurcik W,Bearavolv R,et al.NVisionIP: An Interactive Network Flow Visualization Tool for Security[C]∥Proc of IEEE Int'l Conf on Systems,Man&Cybernetics,2004:2675-2680.
  • 8Agarwal S,Agrawal R,Deshpande P M,et al.On the Computation of Multidimensional Aggregates[C]∥Proc of Int'l Conf on Very Large Data Bases,1996:506-521.
  • 9Chen Y,Dong G,Han J,et al.MultiDimensional Regression Analysis of TimeSeries Data Streams[C]∥Proc of Int'l Conf on Very Large Data Bases,2002:323-334.

同被引文献9

引证文献1

二级引证文献19

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部