• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2011, Vol. 33 ›› Issue (8): 8-13.

• 论文 • 上一篇    下一篇

一种基于流立方体的网络安全态势感知模型

程文聪1,邹鹏2,贾焰2   

  1. (1.空军装备研究院航空气象防化研究所,北京 100085;2.国防科学技术大学计算机学院,湖南 长沙 410073)
  • 收稿日期:2009-09-15 修回日期:2010-01-25 出版日期:2011-08-25 发布日期:2011-08-25
  • 作者简介:程文聪(1981),男,河北邯郸人,博士生,研究方向为数据挖掘和网络安全等。

A Network Security Situation Awareness Model Based on Stream Cube

CHENG Wencong1,ZOU Peng2,JIA Yan2   

  1. (1.Institute of Aeronautical Meteorology and Chemical Defense,Equipment Academy of Air Force,Beijing 100085;
    2.School of Computer Science,National University of Defense Technology,Changsha 410073,China)
  • Received:2009-09-15 Revised:2010-01-25 Online:2011-08-25 Published:2011-08-25

摘要:

网络安全态势感知是网络安全监控技术一个新的发展方向,对网络安全态势的掌握对于网络安全而言具有重要的意义。在已有的关于数据立方体模型的研究基础之上,本文提出了一种基于流立方体模型的网络安全态势感知模型,以描述和抽象化网络安全态势感知中涉及的多维分析结构,从网络安全事件统计数据流的数据特征出发分析网络安全态势。给出了基于频率、趋势和熵值这三种数据特征的模型实例,利用流立方体相邻层次间单元的关系证明了这三种数据特征可以只从原始数据计算底层单元的特征,而上层单元的数据特征则可以通过对底层数据特征的运算而直接得到,从而实现高效计算。实际应用系统的构建和利用网络安全数据的测试实验表明了所提模型和方法的有效性。

关键词: 信息安全, 网络安全态势感知, 数据立方体, 数据流

Abstract:

Network security situation awareness is a new trend of network security monitoring technology. The awareness of the situation is very important to network security. Based on the existing research about data cube, we propose a network security situation awareness model to describe and abstract the multidimensional analysis structure related to the network security situation awareness. We can analyze the network security situation from the aspect of the network security events’ statistical characteristics based on this model and give an instance of the model based on frequency, trend and entropy characteristics. Then we improve the efficiency of the method by studying the correlation of the cells among the neighboring levels in the data cube on the basis of keeping the accuracy of the results. We also prove that we only need to get the lowest level cube’s characteristics from the raw data, and get the higher level cube’s characteristics by an indirect way. Building the practical applications and extensive experiments based on the real network security dataset demonstrates the effectiveness of the proposed model and methods.

Key words: information security;network security situation awareness;data cube;data stream