作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (22): 146-147. doi: 10.3969/j.issn.1000-3428.2006.22.053

• 安全技术 • 上一篇    下一篇

基于多组件分析的报警融合

余彦峰,张书杰,吕罗文   

  1. (北京工业大学计算机学院,北京 100022)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-10-20 发布日期:2006-10-20

Alert Fusion Based on Multi-component Analysis

YU Yanfeng, ZHANG Shujie, LV Luowen   

  1. (College of Computer, Beijing University of Technology, Beijing 100022)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-10-20 Published:2006-10-20

摘要: 报警融合包括报警的规范、验证、聚合和关联,基于多组件分析的报警融合模型能实现报警融合的各个环节,成为安全管理和入侵检测领域研究的前沿课题。实验结果证明,该模型是可行的、有效的。

关键词: 网络安全, 安全管理, 报警融合, 攻击场景

Abstract: Alert fusion includes alert normalization, verification, aggregation and correlation. Alert fusion model based on multi-component analysis can implement each aspect of alert fusion. The module is the leading issue of safety management and research of intrusion detection field. Experimental results show that the model is effective and efficient.

Key words: Network security, Security management, Alert fusion, Attack scenario