论文部分内容阅读
为减少入侵检测系统产生的大量相互独立的警报信息并揭示警报背后所蕴含的攻击策略,将警报处理过程分为相互联系的两个方面:横向关联和纵向关联.通过对相似警报的聚类融合,实现警报横向关联,降低警报数量;以横向关联的结果作为纵向关联的输入,通过分析在一定时间窗内发生警报的因果关系,实现警报的纵向关联,剔出虚假警报,揭示攻击者所采取的攻击策略.实验结果表明,在发生密集型攻击时采用混合关联策略仍能实现高检测率、低误警率的目标,同时能够刻画出警报之间的关联关系.该研究成果对于网络安全态势预测研究具有重要的参考价值.
In order to reduce a large number of independent alarm information generated by intrusion detection system and to reveal the attack strategy behind the alarm, the alarm processing is divided into two interrelated aspects: horizontal and vertical. By clustering similar alarm , To realize the horizontal correlation of the alerts and reduce the number of the alerts. The horizontal correlation results are used as the input of the vertical correlation. By analyzing the causal relationship of the alerts within a certain time window, the vertical correlation of the alerts is realized. The false alarms are removed to reveal the attackers’ The experimental results show that hybrid correlation strategy can still achieve the goal of high detection rate and low false alarm rate in the case of intensive attacks and can also depict the correlation between the alerts.The results of this research are of great value to the network security situation Prediction research has important reference value.