期刊文献+

多源日志聚合分析方法 被引量:1

Method of multi-source log aggregation analysis
下载PDF
导出
摘要 在检测网络安全威胁事件时,各种安全设备会产生大量冗余告警信息,易导致误报率高和日志聚合后聚合度低,给日志分析带来很大困难。为解决这一问题,采用一种自适应时间阈值间隔的聚类算法。通过定义聚合规则和中间日志,动态更新中间日志里的间隔阂值,实现对多源日志的聚合。实验结果表明,该算法的聚合时间阈值间隔更加接近真实攻击时间间隔,能准确对多源日志进行聚合分析,有效减少告警日志信息的数量,提高了日志的聚合度和准确率。 When detecting network security threat incidents,various security devices generate a lot of redundant alarm information,which is easy to cause high false alarm rate and low degree of polymerization of log aggregation,bringing great difficulties to the log analysis.To solve this problem,an improved clustering algorithm of adaptive time threshold interval was proposed.By defining the aggregation rules and middle log,the interval threshold in the middle log was updated dynamically,which realized the aggregation of multi-source log.Experimental results show that the proposed algorithm is much closer to the real attack time interval,and it can accurately analyze multi-source log aggregation,which can effectively reduce the number of alarm log information and improve the log of the polymerization degree and accuracy.
出处 《计算机工程与设计》 北大核心 2017年第7期1702-1708,共7页 Computer Engineering and Design
基金 民航局科技基金项目(MHRD20140205 MHRD20150233) 中央高校基本科研业务费中国民航大学专项基金项目(3122013Z008 3122013C004 3122015D025) 中国民航大学科研启动基金项目(2013QD24X)
关键词 网路安全 多源日志 聚合规则 自适应间隔阈值 日志聚合 network security multi-source log aggregation rules adaptive interval threshold value log aggregation
  • 相关文献

参考文献4

二级参考文献30

  • 1姜传菊.网络日志分析在网络安全中的作用[J].现代图书情报技术,2004(12):58-60. 被引量:19
  • 2龚俭,梅海彬,丁勇,魏德昊.多特征关联的入侵事件冗余消除[J].东南大学学报(自然科学版),2005,35(3):366-371. 被引量:13
  • 3马琳茹,杨林,王建新,唐鑫.利用模糊聚类实现入侵检测告警关联图的重构[J].通信学报,2006,27(9):47-52. 被引量:4
  • 4郭帆,余敏,叶继华.一种基于分类和相似度的报警聚合方法[J].计算机应用,2007,27(10):2446-2449. 被引量:11
  • 5DEAN J,GHEMAWAT S.Map Reduce:simplified data processing on large clusters[J].Communications of the ACM,2008,51(1):107-113.
  • 6GHEMAWAT S,GOBIOFF H,LEUNG S T.The Google file system[J].ACM SIGOPS Operating Systems Review,2003,37(5):29-43.
  • 7SHVACHKO K,KUANG H,RADIA S,et al.The Hadoop dis-tributed file system[C]//2010 IEEE 26th Symposium on MassStorage Systems and Technologies(MSST).[S.l.]:IEEE,2010:1-10.
  • 8CHANG F,DEAN J,GHEMAWAT S,et al.Bigtable:A dis-tributed storage system for structured data[J].ACM Transac-tions on Computer Systems,2008,26(2):4-9.
  • 9Edwards M,Rambani A,Zhu Y,et al.Design of Hadoop based framework for analytics of large synchrophasor datasets[J].Procedia Computer Science,2012,12:254-258.
  • 10McKusick K,Quinlan S.GFS:Evolution on fast-forward[J].Communications of the ACM,2010,53(3):42-49.

共引文献60

同被引文献8

引证文献1

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部