全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

基于机器学习的网络安全态势感知
The Network Security Situation Awareness Based on Machine Learning

DOI: 10.12677/CSA.2020.1012258, PP. 2431-2438

Keywords: 机器学习,态势感知,关联分析,攻击场景重建
Machine Learning
, Network Situation Awareness, Association Analysis, Attack Scene Reconstruction

Full-Text   Cite this paper   Add to My Lib

Abstract:

在传统网络防御手段抵御攻击的基础上,提出了一种利用机器学习的方法来达到网络安全态势感知的新方案。为了有效地获得告警事件,本文引入了告警关联分析的技术,通过分析多源告警信息的关联度从而降低误报率;为了准确地重建攻击场景,本文引入CEP技术处理海量告警信息,并利用基于马尔可夫性质的因果关联分析构建起知识库。分析表明,该方案具有可靠性强、适用性好、计算量小、准确度高的特点,特别适合于大数据环境。
On the basis of the traditional network defense means to resist the attack, a new scheme using machine learning method to achieve network security situational awareness is proposed. In order to obtain alarm events effectively, this paper introduces the technology of alarm correlation analysis, which reduces the false alarm rate by analyzing the correlation degree of multi-source alarm information. In order to reconstruct the attack scene accurately, this paper introduces the CEP technology to deal with the massive alarm information, and uses the causal association analysis based on Markov property to build the knowledge base. The analysis shows that the scheme has the characteristics of strong reliability, good applicability, small calculation amount and high accuracy, and is especially suitable for big data environment.

References

[1]  王莉. 网络多步攻击识别方法研究[D]: [博士学位论文]. 武汉: 华中科技大学, 2007.
[2]  刘必雄. 多源异构日志综合分析技术研究与实践[J]. 南京信息工程大学学报, 2011, 3(4): 365-370.
[3]  冯学伟, 王东霞, 黄敏桓, 等. 一种基于马尔可夫性质的因果知识挖掘方法[J]. 计算机研究与发展, 2014, 51(11): 2493-2504.
[4]  马东君. 网络安全态势感知技术与系统[J]. 网络安全技术与应用, 2013(11): 70-71.
[5]  胡卫华, 张利, 刘锡峰. 安全事件采集关键技术研究与实现[J]. 计算机应用与软件, 2012, 29(12): 309-314
[6]  王文槿, 刘宝旭. 一种基于关联规则挖掘的入侵检测系统[J]. 核电子学与探测技术, 2015(2): 119-123.
[7]  冯学伟. 一种基于概率转移的Cyber攻击场景感知推理技术[J]. 指挥与控制学报, 2015(1): 62-67.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133