• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2013, Vol. 35 ›› Issue (3): 72-79.

• 论文 • Previous Articles     Next Articles

HS-streamCube:Realtime multidimensional
analysis system on network security event stream  

GAN Liang1,2,LI Runheng1,JIA Yan1,LIU Jian3   

  1. (1.School of Computer Science,National University of Defense Technology,Changsha 410073;2.The Second Artillery Command College,Wuhan 430012;3.Troop of 96167,Yongan 366000,China)
  • Received:2010-09-04 Revised:2010-12-15 Online:2013-03-25 Published:2013-03-25

Abstract:

In the applications of largescale network security monitoring,data stream of security events is analysised realtimely to acquire the characteristic of current security in the network and to assess dynamically the current security situation with Stream OLAP by building Stream Cube.Because of the limited memory capacity, Stream Cube only concerned about the current data within the time window,but expired data is stored approximately or simply discarded,so it do not support the query with time beyond the scope of current time window.We propose a realtime StreamCubebased multidimensional and multilevel analysis framework on security event stream, Hybrid StorageStreamCube,which is implemented by a twotier (memory and disk) storage model.On the basis of characteristics of data stream,we focus on the modeling,building,storing and querying of HSStreamCube within the twotier storage model.Efficient experiments verify the availability and efficiency of the system.   

Key words: stream cube;network security event;hybrid storage;OLAP