摘要
各类网络安全防御设备产生的大量冗余告警信息非常琐碎、误警率高,给告警的分析和理解造成较大困难。针对这一问题进行研究,提出一种改进的多源异构告警数据的聚合方案,综合分析告警类型、源IP、目的 IP、目的端口及时间间隔几个属性,总结出四个规则,并在聚合过程中动态更新时间间隔阈值,提高聚合精确度。实验结果表明,这种方法能高效减少异构告警信息的数量,得到精简的超告警数据,并实现了实时处理告警信息的能力。
Various types of network security devices generated a large number of redundant alarm information with the high rate of false alarms. Alarm information is very trivial which is more difficult to analysis and understand the alarm. In order to research this problem, this paper proposed an alert aggregation method for muhi-source heterogeneous alarm. By analyzing alarm type, source IP, destination IP, destination port and time interval, it summed up four rules, dynamically updated the time interval threshold and improved degree of accuracy. The experimental results show that this method can efficiently reduce the number of heterogeneous alarm information, get simplified super alarm data, and realize the real-time processing ability of the alarm information.
出处
《计算机应用研究》
CSCD
北大核心
2014年第2期579-582,共4页
Application Research of Computers
基金
四川省科技支撑计划项目(11ZS2010)
四川省教育厅科研资助项目(11ZB108
10ZD1116)
西南科技大学博士研究基金资助项目(10ZX7132
11ZX7126)
关键词
多源异构
告警聚合
时间阈值
动态更新
multi-source heterogeneous
alert aggregation
time threshold
dynamic updates