基于Drools的离线分析研究与实现  

Off-line Analysis Research and Implementation Based on Drools

在线阅读下载全文

作  者:修洁蕾[1] 许南山[1] 危胜军[2] 

机构地区:[1]北京化工大学信息学院计算机系,北京100029 [2]北京理工大学计算机网络攻防对抗技术实验室,北京100081

出  处:《微计算机信息》2009年第3期148-149,134,共3页Control & Automation

摘  要:提出了一种基于Drools离线分析的方法,是对主机监控系统实时分析无法深入的一种补充。对监控系统产生的海量警报信息进行压缩,对攻击事件的发生过程进行安全事件关联分析。首先介绍了Drools的工作原理,然后基于系统整体模型,给出了规则推理的详细设计策略和关键技术的实现。最后进行了离线分析仿真试验,U盘监控类离线分析结果表明警报信息数量的压缩率在9.898%以上并得到了攻击(操作)过程。A kind of offline analysis based on Drools was proposed, h was a complementarily to real-time analysis of the host detection system. It not only compressed the large quantity of alerts generated by monitoring system, but also accomplished the security events association on the whole operation procedure. Firstly, general model was construeted based on the Drools principle. Secondly, the detailed design tactics and the key technologies realization were provided. Finally the off-line simulation results using the flash memory disks alerts showed that the quantity compressibility of alerts was above 9.898% and the attack (operation) procedure was successfully achieved.

关 键 词:主机监控系统 离线分析 安全事件关联 DROOLS 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象