期刊文献+

基于场景重构和报警融合的异常数据分析

下载PDF
导出
摘要 本文提出了一种包含报警标准化、去冗余、场景重构和报警融合的异常数据分析方法 ,通过去除攻击失败的报警,减少了对场景重构的干扰。在场景重构中,通过反向关联,减少了不必要的报警,同时通过对孤立报警的补充,保证了场景图的完整性。在报警融合中,提出了融合同一攻击步骤的不同报警的方法,以抽象层和具体层两个层次重构入侵场景。最后通过实验验证了所提出方法的有效性。 This paper proposes an abnormal data analysis method which contains alarm standardization, eliminating redundancy, scene reconstruction and alarm fusion . The interference of scene reconstruction is reduced by removing the alarm of failed attacks. In the reconstruction of the scene, through reverse link, reduced the unnecessary evidence, at the same time through the addition to the isolated alarm, to ensure the integrity of the scene graph .Herein, to reconstruct intrusion scenario in abstract and concrete layer, we also developed different alerting methods based fusion of the same attack steps in the alarm fusion. Finally the effectiveness of the proposed method is verified by experiment.
出处 《科技视界》 2015年第15期7-7,163,共2页 Science & Technology Vision
关键词 异常数据分析 去冗余 场景重构 报警融合 Abnormal data analysis Eliminating redundancy Scene reconstruction Alarm fusion
  • 相关文献

参考文献4

  • 1Moradi M,Zulkemine M.A neural network based system for intrusion detection and classification ofattacks[J].Queen University,Canada,2004:1008-1015.
  • 2Daisuke Takahashi,Yang Xiao.Com Plexity Analysis of Retrieving Knlowledge from Auditing Log Files for Com Puter and Network Forensics and Accountability[C]//IEEE International Conference on Communieations,IEEE.May,2008:1474-1478.
  • 3Achi H,Hellany A,Nagrial M.Network security approach for digital forensics analysis[C]//Computer Engineering&Systems,2008.ICCES 2008.International Conference on.IEEE,2008:263-267.
  • 4Peng N,Yun C,Douglas S.Techniques and tools for analyzing intrusion alerts[J].ACM Trans on Information and System Security,2004,7(2):274-318.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部