%0 Journal Article %T Alarm correlation analysis based on SVM and fuzzy logic
基于SVM和模糊逻辑的告警相关性分析* %A ZHANG Ya-pu %A MENG Xiang-ru %A ZHANG Li %A MA Hai-yuan %A
张亚普 %A 孟相如 %A 张立 %A 麻海圆 %J 计算机应用研究 %D 2011 %I %X This paper proposed an alarm correlation algorithm based on support vector machine(SVM) and fuzzy logic to solve the problems of poor dynamic adaptability, high false alarm rate and so on, which were existing in the alarm correlation of network fault diagnosis. For the problems of network uncertainty and nonstandard data formats, sliding time window,fuzzy time series and feature statistics were employed in the data pre-processing part. The alarm correlation part was realized through the training and identificating of SVM. Experiment on DARPA intrusion detection evaluation data set shows that the algorithm has lower false alarm rate,higher compression ratio and better dynamic adaptability, which improve the efficiency of alarm correlation. %K network fault diagnosis %K support vector machine %K alarm correlation %K fuzzy logic
网络故障诊断 %K 支持向量机 %K 告警关联 %K 模糊逻辑 %U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=A9D9BE08CDC44144BE8B5685705D3AED&aid=FDB0B4FA6AEA773A448C595C1C9BD6C1&yid=9377ED8094509821&vid=D3E34374A0D77D7F&iid=0B39A22176CE99FB&sid=AF14A8B15FB15A64&eid=2A22E972FD97071B&journal_id=1001-3695&journal_name=计算机应用研究&referenced_num=0&reference_num=9