• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2012, Vol. 34 ›› Issue (7): 39-45.

• 论文 • 上一篇    下一篇

网络态势感知中的报警记录觉察研究

王娟1,彭静2,王灿3   

  1. (1.成都信息工程学院网络工程学院,四川 成都 610225;2.成都信息工程学院教务处,四川 成都 610225;
    3.电子科技大学计算机科学与工程学院,四川 成都 610054)
  • 收稿日期:2011-07-24 修回日期:2011-10-09 出版日期:2012-07-25 发布日期:2012-07-25
  • 基金资助:

    成都信息工程学院科研基金资助项目(KYTZ201121)

Research on Alert Records Perception of Network Situation Awareness

WANG Juan 1,PENG Jing2,WANG Can3   

  1. (1.School of Network Engineering,Chengdu University of Information Technology,Chengdu 610225;
    2.Academic Affairs Office,Chengdu University of Information Technology,Chengdu 610225;
    3.School of Computer Science and Engineering,
    University of Electronics Science and Technology of China,Chengdu 610054,China)
  • Received:2011-07-24 Revised:2011-10-09 Online:2012-07-25 Published:2012-07-25

摘要:

网络态势感知中的报警觉察在处理粒度、规模、目标等方面均不同于传统入侵检测中的报警分析,更加侧重于人的理解。本文在现有基于相似度报警分析方法的基础上设计了一种“基于相似度的宏观网络报警觉察算法”,重新定义了报警属性相似度,将“优序对比法”引入属性权重设定,最后提出以“人的瞬时理解力”为依据的阈值选择方案。实验显示该方法能帮助网络管理人员从整体上把握网络异常的时间、范围、类型,理解网络的态势。

关键词: 网络态势感知, 报警分析, 入侵检测, 相似度

Abstract:

The alert perception of network situation awareness is different from that of the traditional intrusion detection area in particle size, scale, target, and so on. It pays more attention to human understanding. Based on the existing similarity based alert analysis method, a "similarity based macro network alert awareness algorithm" is proposed. It gives a new definition of attribute similarity, and uses an "optimal sequence method" to improve attribute weight setting. Finally, a threshold selection scheme is proposed  based on human instantaneous understanding. The experimental results show that this method can help network managers get the whole awareness of network situation including the time, range, and type of network abnormality.

Key words: network situation awareness;alert analysis;intrusion detection;similarity