首页 | 本学科首页   官方微博 | 高级检索  
     

一种计算网络告警因果关联置信度的新方法
引用本文:张少俊,李建华,宋四根,陈秀真. 一种计算网络告警因果关联置信度的新方法[J]. 解放军理工大学学报(自然科学版), 2009, 10(3): 215-218
作者姓名:张少俊  李建华  宋四根  陈秀真
作者单位:上海交通大学信息安全工程学院,上海200240;上海市信息安全综合管理技术研究重点实验室,上海200240;解放军61398部队,上海,200137
基金项目:国家863计划资助项目,国家自然科学基金资助项目,教育部博士点基金资助项目 
摘    要:为提高告警因果关联准确性,提出了将实施单次攻击所需的时间消耗作为随机变量,给出其概率分布模型,在此基础上计算任意2条因果相关告警的时间关联置信度。设计并实现了算法验证程序,利用DARPA 2000入侵检测数据集进行了验证。结果表明,新方法合理地量化了告警时间关联置信度,且计算复杂度低,能为正确关联攻击场景提供支持。

关 键 词:网络安全  告警关联  攻击耗时  关联置信度

Novel method to calculate causal correlation belief values of network alerts
ZHANG Shao-jun,,LI Jian-hua,SONG Si-gen,CHEN Xiu-zhen. Novel method to calculate causal correlation belief values of network alerts[J]. Journal of PLA University of Science and Technology(Natural Science Edition), 2009, 10(3): 215-218
Authors:ZHANG Shao-jun    LI Jian-hua  SONG Si-gen  CHEN Xiu-zhen
Affiliation:1.School of Information Security Engineering;Shanghai Jiao Tong University;Shanghai 200240;China;2.Shanghai Key Laboratory for Information Security Integrated Management Technology Research;3.Unit 61398 of PLA;Shanghai 200137;China
Abstract:In order to improve the precision of alert correlation,a network security alert correlation method based on the attack time consumption model was proposed.The attack time consumption was taken as a random variable and its probabilistic distribution was defined.Based on the distribution,the temporal correlation belief metric of any two alerts which might have potential causal relationship could be calculated.To testify the feasibility,a prototype system was designed,implemented and tested with the DARPA 2000...
Keywords:network security  alert correlation  attack time expense  correlation belief  
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《解放军理工大学学报(自然科学版)》浏览原始摘要信息
点击此处可从《解放军理工大学学报(自然科学版)》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号