作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (13): 280-282.

• 开发研究与设计技术 • 上一篇    下一篇

安全事件关联分析引擎的研究与设计

熊云艳 1, 2,毛宜军2, 3,丁志 3, 4   

  1. 1. 广东工贸职业技术学院计算机系,广州 510510;2. 华南理工大学计算机科学与工程学院,广州 510640;3. 华南农业大学信息学院,广州 510640;4. 广东省考试中心,广州 510641
  • 出版日期:2006-07-05 发布日期:2006-07-05

Research and Design of Correlation Analysis Engine for Security Incident

XIONG Yunyan1, 2, MAO Yijun2, 3, DING Zhi3, 4   

  1. 1. Department of Computer, Guangdong Vocational College of Industry, Guangzhou 510510; 2. College of Computer Science & Engineering, South China University of Technology, Guangzhou 510640; 3. College of Information, South China Agricultural University, Guangzhou 510640;4. Center of Examination in Guangdong Province, Guangzhou 510641
  • Online:2006-07-05 Published:2006-07-05

摘要: 入侵检测系统是动态安全防御里的重要环节,现有的入侵检测系统(IDS)存在一个致命的缺陷:误报率高居不下,IDS 无法展现事件之间的逻辑关系,结果用户很难了解事件背后隐藏的攻击策略或逻辑步骤。为了解决IDS 存在的上述问题,在深入分析入侵技术的基础上提出了基于入侵序列的启发式关联方法,设计并实现了一个事件关联分析引擎,最后验证了有效性。

关键词: 入侵检测系统;误报;关联分析;入侵序列

Abstract: Intrusion detection system is one of the dynamic defensive techniques, but current intrusion detection systems (IDSs) usually generate a large amount of false alerts and none of them can capture the logical steps or strategies behind the attacks. As a result, it is difficult for human users to understand the intrusions behind the alerts and take appropriate actions. This paper presents a correlation analysis approach based on the sequences and heuristic arithmetic to address these issues after analyzing large numbers of attack techniques and designs a correlation analysis engine for security incident and conducts one experiment to demonstrate the potential of the system, in reducing false alerts and uncovering attack strategies.

Key words: Intrusion detection systems (IDSs); False alert; Correlation analysis; Intrusion consequence