摘要
为提高网络的可用性和可靠性 ,当网络出现异常时 ,首先 ,必须尽快地发现异常 (即异常检测 ) ,发出警报 ,这样可以提前采取措施以避免或减轻对服务的影响 ,其次 ,必须从大量的警报信息中作出正确的诊断 ,提取出真正的、非冗余的信息 ,以便找出问题的根源 (即警报关联 ) ,从而解决问题 ,改善服务质量 .本文就网络异常检测和警报关联两个方面进行总结和分析 ,回顾了该领域的主要研究工作 。
To improve its availability and dependability, when anomaly occurs in network, firstly, it must be detected as soon as possible (i.e., anomaly detection), then the alarms can be sent out, so the correcting actions can be taken to avoid impact or alleviate loss. Secondly, the numerous alarms must be correlated and the true and non redundant information may be extracted, which is helpful to find the real problem and resolve it, so the quality of service may be improved. In this paper, summarizations and analyses on anomaly detection and alarm correlation was made, the research work in this field was reviewed. Finally, a new method for anomaly detection is proposed.
出处
《小型微型计算机系统》
CSCD
北大核心
2004年第4期506-510,共5页
Journal of Chinese Computer Systems
基金
国家重大基金项目资助 ( 90 10 40 0 6)资助
国家 863计划 ( 2 0 0 1AA112 13 5
2 0 0 1AA112 0 91)资助
关键词
网络异常
异常检测
警报关联
network anomaly
anomaly detection
alarm correlation