摘要: 入侵检测系统是动态安全防御里的重要环节,现有的入侵检测系统(IDS)存在一个致命的缺陷:误报率高居不下,IDS 无法展现事件之间的逻辑关系,结果用户很难了解事件背后隐藏的攻击策略或逻辑步骤。为了解决IDS 存在的上述问题,在深入分析入侵技术的基础上提出了基于入侵序列的启发式关联方法,设计并实现了一个事件关联分析引擎,最后验证了有效性。
关键词:
入侵检测系统;误报;关联分析;入侵序列
Abstract: Intrusion detection system is one of the dynamic defensive techniques, but current intrusion detection systems (IDSs) usually generate a large amount of false alerts and none of them can capture the logical steps or strategies behind the attacks. As a result, it is difficult for human users to understand the intrusions behind the alerts and take appropriate actions. This paper presents a correlation analysis approach based on the sequences and heuristic arithmetic to address these issues after analyzing large numbers of attack techniques and designs a correlation analysis engine for security incident and conducts one experiment to demonstrate the potential of the system, in reducing false alerts and uncovering attack strategies.
Key words:
Intrusion detection systems (IDSs); False alert; Correlation analysis; Intrusion consequence
熊云艳 ,毛宜军,丁志. 安全事件关联分析引擎的研究与设计[J]. 计算机工程, 2006, 32(13): 280-282.
XIONG Yunyan, MAO Yijun, DING Zhi. Research and Design of Correlation Analysis Engine for Security Incident[J]. Computer Engineering, 2006, 32(13): 280-282.