作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (16): 128-129,. doi: 10.3969/j.issn.1000-3428.2007.16.044

• 安全技术 • 上一篇    下一篇

基于日志的安全事件管理系统的研究与实现

余亚玲1,唐红武2,杜海霞1   

  1. (1. 华北计算技术研究所,北京100083;2. 中国民航信息集团研发中心,北京100027)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-20 发布日期:2007-08-20

Research and Implementation of Security Event Management System Based on Log

YU Ya-ling1, TANG Hong-wu2, DU Hai-xia1   

  1. (1. North China Institute of Computing Technology, Beijing 100083; 2. TravelSky Technology Group Research Center, Beijing 100027)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-20 Published:2007-08-20

摘要:

给出了一个以日志分析为基础、结合关联规则与联动技术的安全事件管理系统(SYMCLOG)的框架及其实现,分析了日志处理的关联规则,根据日志数据的特点,结合数据挖掘技术对日志挖掘的Apriori算法进行了优化和改进,提高了SYMCLOG系统的实时响应能力与联动性,探讨了如何根据日志的处理结果进行事件的联动。

关键词: 日志分析, 关联规则, SYMCLOG, 联动

Abstract: This paper analyses the technologies of event management system based on log and gives out the realization frame. It focuses on analyzing association rules of log disposition. And according to the characteristics of log, it optimizes log data mining algorithm——Apriori algorithm with the technology of data mining, which improves the interaction, security and real-time responsibility of the system. It also probes into the event interaction based on the result of handling log.

Key words: log analysis, association rule, SYMCLOG, interaction

中图分类号: