检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]国防科学技术大学计算机学院,长沙410073
出 处:《计算机工程与应用》2012年第13期57-62,104,共7页Computer Engineering and Applications
基 金:国家自然科学基金(No.61003303);国家高技术研究发展计划(863)(No.2009AA01Z432)
摘 要:针对分布式入侵检测和网络安全预警所需要解决的问题,对多传感器数据融合技术进行了研究。在分析IDS警报信息之间的各种复杂关系的基础上,提出了一个警报信息实时融合处理模型,并根据该模型建立警报信息融合处理系统。实时融合来自多异构IDS传感器的警报信息,形成关于入侵事件的攻击序列图,在此基础上进行威胁评估及攻击预测。该模型拓展了漏报推断功能,以减少漏报警带来的影响,使得到的攻击场景更为完整。实验结果表明,根据该模型建立的融合处理系统应用效果好,具有很高的准确率和警报缩减率。To resolve the problem which distributed intrusion detection and network attack warning system has to confront, multi-sensor data fusion techniques are studied. Based on the analysis of various complex relationships of IDS alerts, this paper presents an alerts information real-time fusion model. An alerts information real-time fusion system based on it is realized, which can real-time fuse alarms from various heterogeneous IDS sensors, generate attack sequence view about intrusion, evaluate threaten and predict potential attacks. Furthermore, the function of reasoning false negative is introduced, which aims at reduce adverse effects of missed alerts and builds more integrated attack scenarios. Experimental results show that the real-time fusion system on this model works effectively, it has high accuracy and high alarm reduction rate.
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.113