计算机工程与应用 ›› 2007, Vol. 43 ›› Issue (4): 143-145.

• 网络、通信与安全 • 上一篇    下一篇

基于事件关联的网络威胁分析技术研究

张翔 胡昌振 尹伟   

  1. 北京理工大学计算机网络攻防对抗技术实验室 北京理工大学机电工程与控制国家重点实验室网络安全分室
  • 收稿日期:2006-03-03 修回日期:1900-01-01 出版日期:2007-02-01 发布日期:2007-02-01
  • 通讯作者: 张翔

Research of Network Threat Analysis Technique Based On Event Correlation

  • Received:2006-03-03 Revised:1900-01-01 Online:2007-02-01 Published:2007-02-01

摘要: 文章应用事件关联的方法综合IDS等安全设备报警信息进行网络威胁分析,介绍了事件关联基本方法,并提出事件关联分析器体系结构,实验系统测试结果表明,应用事件关联技术有效降低了网络威胁分析中出现的虚警,极大地减少了冗余报警。

Abstract: The presentation is about network threat analysis accord to alert information of IDS and other network security devices in event correlation method. First some basic methods of event correlation was introduced, then a structure of event correlation analysis engine was discussed. Test result of demo system proved applying event correlation method on the threat analysis decreased the false positive and redundant alarm from network security devices.