期刊文献+

基于Windows日志分析的终端安全研究 被引量:4

Research on terminal security based on Windows event log analysis
下载PDF
导出
摘要 网络安全已经上升到关系国家主权战略问题,受到广泛的重视。近年越来越多的新型攻击方式不断涌现,对于这些无法防范的安全威胁,经过正确配置和记录的系统日志便发挥出其价值。尤其对于大型企业,其系统日志是冗杂且数量庞大,完整性也经常遭到人为的破坏。论文介绍了Windows操作系统的日志结构,利用已有的日志分析辅助工具和批量处理工具,讨论如何更高效地利用系统日志完成安全事件的溯源,并查找系统未知漏洞以进行修补,最终给出系统日志分析的基本模型。 Network security has risen to the relationship between national sovereignty strategic issues,and has been widely attention.Recently more and more completely new attacking methods appeared on the network.The event log is getting valuable because we can’t defend those threats.But the event log of a system is redundant and in a large amount,especially for enterprise.And the integrality of the log is always destroyed factitiously.This passage will introduce the struct of Windows event log and discuss about how to originate the source of the security accident and find vulnerabilities to repair.Finally,will give out basic model of system log analysis.
作者 李春强 夏伟 Li Chunqiang;Xia Wei(Beijing Information Science and Technology University/Beijing Jingwei Xinan Technology Co. Ltd., Beijing 100101)
出处 《网络空间安全》 2018年第9期70-77,共8页 Cyberspace Security
关键词 日志分析 终端安全 企业内网安全 event log analysis terminal security corporation intranet security
  • 相关文献

参考文献1

二级参考文献5

  • 1[1]anderson J P.Computer Security Threat Monitoring and Surveillance Fort Washington,James P.Anderson Co.,1980
  • 2[2]Matt B,Christopher W,Jeremy F.Goal-oriented Auditing and Logging IEEE Transactions on Computing Systems,1996
  • 3[3]Price K E.Hostbased Misuse Detection and Conventional Operating Systems audit Data Collection[Masters Thesis].Purdue University 1997-12
  • 4[4]Giovanni V,Inspect:A Lightweight Distributed Approach to Autom-ated Audit Trail Analysis.http://citeseer.nj.nec.com/276699.html
  • 5[5]Daniels T E,Spafford E H.A Network Audit System for Hostbasted Intrusion Detecti(NASHID)in Linux.Purdue University,2000

共引文献34

同被引文献20

引证文献4

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部