作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (17): 173-175. doi: 10.3969/j.issn.1000-3428.2007.17.059

• 安全技术 • 上一篇    下一篇

入侵检测报警关联技术

姜兆元,赵 军   

  1. (重庆邮电大学计算机科学与技术研究所,重庆 400065)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-09-05 发布日期:2007-09-05

Intrusion Detection Alert Correlation Techniques

JIANG Zhao-yuan, ZHAO Jun   

  1. (Inst. of Comp. Sci. & Tech., Chongqing Univ. of Posts and Telecom., Chongqing 400065)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-09-05 Published:2007-09-05

摘要: 报警关联技术分析不同安全产品产生的报警,从中识别出真正有意义的攻击警报,并减少大量的误报警,降低安全管理员的工作量。该文介绍了报警关联的基本模型和主要技术,分析了主要的关联方法,探讨了报警关联技术的发展方向。这些讨论对应用或发展报警关联技术都有参考价值。

关键词: 入侵检测, 报警关联, 网络安全

Abstract: Many intrusion detection technologies are complementary to each other. The alert correlation technology analyzes alerts generated from different security products, so that false alerts are greatly reduced, real attacks are more easily discerned, accordingly, the work load on system administrators is largely released. Herein, basic models and technologies of alert correlation are discussed. Important correlation algorithms are analyzed; and development tendencies of alert correlation technologies are also predicted.

Key words: intrusion detection, alert correlation, network security

中图分类号: