期刊文献+

网络安全告警降噪基线的智能生成方法

Intelligent Generation Method of Noise Reduction Baseline for Cybersecurity Alert
下载PDF
导出
摘要 网络安全运营往往通过预置的基线规则组等方法来过滤告警,在复杂的场景中难以深入适配企业的具体网络和业务环境.随着企业信息化业务的不断扩展,复杂的网络攻击通常隐藏在海量告警中,造成告警疲劳的现象,严重影响安全运营团队的运营效率.提出一种智能的算法用于生成可解释的网络安全告警降噪基线.面向告警载荷进行数据挖掘建立基线,帮助运营人员在不了解公司环境和业务的情况下对海量的告警进行过滤,提升安全运营的效率.最终,在某大型公司的实际生产环境验证发现生成的降噪基线可以有效地过滤告警. The operators often filter alerts through some preset baseline rule groups in cybersecurity operation.It is difficult to deeply adapt to the specific network and business environment of the enterprise.With the continuous expansion of enterprise information services,the complex cyberattack is usually hidden in tons of alerts.It causes the alert fatigue,which reduces the efficiency of security operation center.We propose a cybersecurity alert baseline method based on intelligence algorithm to generate interpretable alert noise reduction baselines,which can filter alerts without understanding the company's environment and business.It can improve the efficiency of cybersecurity operation.This method can effectively filter alerts in the actual production environment of a large company.
作者 王星凯 吴复迪 童明凯 薛见新 张润滋 Wang Xingkai;Wu Fudi;Tong Mingkai;Xue Jianxin;Zhang Runzi(NSFOCUS Technologies Group Co.,Ltd.,Beijing 100089;School of Information Science and Technology,Tsinghua University,Beijing 100084)
出处 《信息安全研究》 CSCD 2023年第10期986-992,共7页 Journal of Information Security Research
基金 北京市科技新星计划项目(Z211100002121150)。
关键词 告警 载荷 可解释基线 告警降噪 安全运营 alert payload interpretable baseline alert noise reduction security operation
  • 相关文献

参考文献1

二级参考文献1

共引文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部