计算机工程与设计
計算機工程與設計
계산궤공정여설계
Computer Engineering and Design
2015年
11期
2953-2957
,共5页
吴朝雄%王晓程%王红艳%石波
吳朝雄%王曉程%王紅豔%石波
오조웅%왕효정%왕홍염%석파
网络安全%威胁态势%RS%ESP%实时%复杂攻击
網絡安全%威脅態勢%RS%ESP%實時%複雜攻擊
망락안전%위협태세%RS%ESP%실시%복잡공격
network security%threat situation%rough set%event stream processing%real-time%complex attack
针对目前网络安全威胁态势分析实时性不足以及对复杂攻击感知敏感度不高的问题,设计实时感知系统结构模型,提出相应的感知方法和分析技术。通过粗集(rough set , RS),从已有的组合攻击样本数据集中提取复杂攻击规则,结合事件流处理技术(event stream processing , ESP),实现对安全事件流的在线动态分析检测,提高对复杂攻击的感知能力,提升网络安全威胁态势分析的实时性和客观性。实验验证了该方法的有效性和可行性。
針對目前網絡安全威脅態勢分析實時性不足以及對複雜攻擊感知敏感度不高的問題,設計實時感知繫統結構模型,提齣相應的感知方法和分析技術。通過粗集(rough set , RS),從已有的組閤攻擊樣本數據集中提取複雜攻擊規則,結閤事件流處理技術(event stream processing , ESP),實現對安全事件流的在線動態分析檢測,提高對複雜攻擊的感知能力,提升網絡安全威脅態勢分析的實時性和客觀性。實驗驗證瞭該方法的有效性和可行性。
침대목전망락안전위협태세분석실시성불족이급대복잡공격감지민감도불고적문제,설계실시감지계통결구모형,제출상응적감지방법화분석기술。통과조집(rough set , RS),종이유적조합공격양본수거집중제취복잡공격규칙,결합사건류처리기술(event stream processing , ESP),실현대안전사건류적재선동태분석검측,제고대복잡공격적감지능력,제승망락안전위협태세분석적실시성화객관성。실험험증료해방법적유효성화가행성。
Aiming at the lack of real‐time analysis of network security threats situation and sensitivity perceived of complex at‐tack ,the architecture of real‐time perceived system was designed ,and the method and analysis technology were proposed .Com‐plex attack rules from the sample were got through rough set (RS) theory .Combining with event stream processing (ESP) tech‐nology ,online dynamic analysis and detection of security event stream was completed .The sensitivity for complex attack was promoted ,so that it can improve the timeliness and objectivity of situation analysis of network security threats .Experiments verifies the effectiveness and feasibility of the proposed method .