Computer Engineering and Applications ›› 2012, Vol. 48 ›› Issue (4): 25-28.

• 博士论坛 • Previous Articles     Next Articles

Research on real-time alert correlation based on increment mining

LIAO Niandong1, XIONG Bing1, HU Qi2   

  1. 1.College of Computer and Communication Engineering, Changsha University of Science and Technology, Changsha 410114, China
    2.College of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China
  • Received:1900-01-01 Revised:1900-01-01 Online:2012-02-01 Published:2012-04-05

增量挖掘实时报警关联研究

廖年冬1,熊 兵1,胡 琦2   

  1. 1.长沙理工大学 计算机与通信工程学院,长沙 410114
    2.北京交通大学 计算机与信息技术学院,北京 100044

Abstract: Intrusion detection technology can remedy effectively the shortcoming of firewall by obtaining the alert information of network attacks, and detecting, analyzing and dynamically defending in according with network security. It is an important research task of intrusion detection technology that improving the detection and accuracy rate by effectively dealing with network alerts information. This paper proposes a novel method of network alert correlation based on real-time increment mining. In this method, the procession of alert aggregation, alert correlation and alert analysis is carried out in the small scale scope. This method effectively overcomes the shortcoming of some data mining methods applied the intrusion detection process, such as: multi-scanning; high false positive rate; low association rate in the alerts information. The experimental results show that this method not only can treat large capacity network alerts information, but also reflects the good performance in the alerts information analysis and alerts event reduction.

Key words: intrusion detection, data mining, alert association, network security

摘要: 入侵检测技术通过实时获取网络攻击报警信息,对网络安全实施检测、分析和动态防御,有效弥补了防火墙的不足。通过有效处理网络报警信息提高入侵检测的检测率、精确度是当前入侵检测技术研究的重要课题之一。提出了一种实时的增量挖掘入侵检测报警关联方法。该方法使报警事件的聚合操作和报警关联分析控制在小规模数据范围内进行,有效克服了一些数据挖掘算法应用到入侵检测过程中存在的多遍扫描、误报率高和报警信息关联度低问题。实验结果表明,该方法不但可以处理大容量实时网络报警信息,而且在报警信息关联分析和报警事件约减都体现了良好的性能。

关键词: 入侵检测, 数据挖掘, 报警关联, 网络安全