%A JU An-kang, GUO Yuan-bo, ZHU Tai-ming and WANG Tong %T Survey on Network Security Event Correlation Analysis Methods and Tools %0 Journal Article %D 2017 %J Computer Science %R 10.11896/j.issn.1002-137X.2017.02.004 %P 38-45 %V 44 %N 2 %U {https://www.jsjkx.com/CN/abstract/article_981.shtml} %8 2018-11-13 %X At present,the frequency of the new network security attacks events represented by APT is increasing,and it is more harmful to the enterprise information infrastructure.The new types of attack have the characteristics of customi-zation,concealment and continuity,and these make it more difficult for traditional detection methods to detect or predict these deep-hidden attacks in time.However,with the development of big data technology,people can correlate the information about security events and system running environment effectively,and this makes it possible to detect new types of attack and threat.In this paper,we expounded the importance of security event correlation analytics,and then discussed the existing correlation analysis techniques from the aspect of event attributes,logical reasoning,statistics and machine learning.Finally we introduced several commonly used open-source correlation analysis software,and synthetically compared them in application scenarios,programming language,user interface,and the correlation method used.