龙春, 申罕骥, 李俊. 基于EA-DS证据理论的安全事件关联分析[J]. 微电子学与计算机, 2015, 32(11): 46-52.
引用本文: 龙春, 申罕骥, 李俊. 基于EA-DS证据理论的安全事件关联分析[J]. 微电子学与计算机, 2015, 32(11): 46-52.
LONG Chun, SHEN Han-ji, LI Jun. Security Events Fusion Based on EA-DS Evidence Theory[J]. Microelectronics & Computer, 2015, 32(11): 46-52.
Citation: LONG Chun, SHEN Han-ji, LI Jun. Security Events Fusion Based on EA-DS Evidence Theory[J]. Microelectronics & Computer, 2015, 32(11): 46-52.

基于EA-DS证据理论的安全事件关联分析

Security Events Fusion Based on EA-DS Evidence Theory

  • 摘要: 为了对多源安全事件进行关联分析,提出了基于EA-DS证据理论的安全事件关联分析方法.该方法结合所在网络环境将来自多个不同种类的安全传感器数据进行证据融合,计算网络服务威胁状态置信度,能够快速发现高威胁状态的服务并采取相应的措施进行响应.通过在实际网络环境中进行实验和对比,该方法有较好的高危攻击发现能力.

     

    Abstract: In order to correlate and analyze multi-source security events, this paper has proposed a security event correlation analysis method which is based on Environment Awareness Dempster-Shafer evidence theory (EA-DS). The method combined various security sensor data in the network environment for evidence fusion, computed threat state confidence of network service, and detected high threat state of the service rapidly. Extensive experiments show that EA-DS has good ability to find high risk threat in the real network environment.

     

/

返回文章
返回