计算机科学 ›› 2010, Vol. 37 ›› Issue (4): 67-70.

• 计算机网络与信息安全 • 上一篇    下一篇

基于报警原因的聚类分析方法

王秀利,海沫,朱建明,章宁   

  1. (中央财经大学信息学院 北京100081)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受国家自然科学基金项目(60970143,70872120,70872119),教育部科学技术研究重点项目(109016,北京市自然科学基金项目(9092014,4082028,北京市教育委员会共建项目专项,中央财经大学"211工程”只期重点学科建设项目,中央财经大学"中财121人才工程”青年博士发展基金项目 (QBG0702)资助。

Clustering Analysis Method Based on Alert Cause

WANG Xiu-li,HAI Mo,ZHU Jian-ming,ZHANG Ning   

  • Online:2018-12-01 Published:2018-12-01

摘要: 针对入侵检测系统产生大量冗余报警的问题,提出基于报警原因的聚类分析方法。根据报警原因把逻辑上相关的报警归类到同一个报警聚类中,聚类中的报警具有相同的属性,进而归纳为泛化报警,并由它描述报警的共同特征,从而极大地减少报警数量,简化报警分析,有利于准确分析出网络和应用环境面临的安全威胁,以及时采取应对措施。

关键词: 入侵检测,报警分析,报警聚类,报警原因,启发式算法

Abstract: The use of intrusion detection has created the problem to investigate a generally large number of alarms. To solve the problem, a clustering analysis method based on alert cause was presented. The correlative alarms with the same attribute were ranged into a clustering according to their causes. The generalized attributes can describe the common characteristic of the alarms. The method can cut down the number of alarms remarkably, simplify the alert analysis, and analyze the security risk in network and application environment accurately. I}herefore, the corresponding measures can be taken in time.

Key words: Intrusion detection, Alert analysis, Alert clustering, Alert cause, Heuristic algorithm

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!