5Cuppens F and Miege A. Alert correlation in a cooperative intrusion detection framework[C]. Proceedings 2002 IEEE Symposium on Security and Privacy. Oakland, 2002: 202- 215.
6Qin X Z and Lee W K. Statistical causality analysis of INFOSEC alert data[C]. Recent Advances in Intrusion Detection 6th International Symposium, Pittsburgh, 2003, Vol. 2820: 73-93.
7Gorodetsky V, Karsaev 0, and Samoilov V. On-line update of situation assessment based on asynchronous data streams[C]. Knowdedge-Based Intelligent Information and Engineering Systems, Wellington, 2004, Vol. 3213: 1136- 1142.
8Yegneswaran V, Barford P, and Paxson V. Using Honeynets for Internet situational awareness[CIOL]. Proceedings of the Fourth Workshop on Hot Topics in Networks, Berlin, 2005. http://www.icir .otg] vein] papers 1 sit-aware- hotnet05. pdf.
9Hariri S, Qu G Z, Dharrnagadda T, et al. Impact analysis of faults and attacks in large-scale networks[J]. IEEE Security & Privacy, 2003, 1(5): 49-54.
10Mohammad Salim Ahmed, Ehab Al-Shaer , Mohamed Taibah, et al. Objective risk evaluation for automated security management[J]. Journal of Network and Systems Management, 2011, 19(3): 343-366.