引入交叉确认机制的安全态势评估模型  被引量:2

Assessment model of security situation introduced cross-validation mechanism

在线阅读下载全文

作  者:吴志刚[1] 苏安婕[1] 王文奇[1] 

机构地区:[1]中原工学院计算机学院,郑州451191

出  处:《计算机工程与应用》2011年第28期106-109,共4页Computer Engineering and Applications

基  金:河南省教育厅自然科学研究基金(No.2011A520049);河南省科技攻关计划项目(No.082102210082)

摘  要:针对当前网络安全态势评估数据源较单一,评估结果欠准确等问题,提出了基于交叉确认机制的安全态势评估模型。该模型根据网络安全事件间的关联性以及告警信息的不确定性,提出多源告警信息交叉确认机制,利用模糊推理将海量的告警信息进行交叉确认,提取出可靠的评估信息,并结合静态评估数据进行安全态势评估。利用实例网络数据,对该模型进行了验证,实验结果表明该模型评估结果的全面性和准确性有很大程度的提高。According to the fact that the data sources of the network security situation assessment are one-sided and the results are not accurate and other issues, this paper proposes a method of network security situation assessment based on cross-validation.On the basis of the correlation of network security events and the uncertainty of alarm information, a kind of cross-validation mechanism on multi-source warnings is presented.Thus, a large amount of data from multi-source warn- ings are identified and confirmed by the mechanism with fuzzy reasoning,and then the situation assessment is implemented on the basis of the extract accurate and tidy attack information with combining static assessment data.An example of actual net- work is given to validate the method.The results show that this method is more effective and accurate than the existing methods.

关 键 词:态势评估 交叉确认 模糊论域 模糊推理 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象