taptap下载安装安卓学报

• 工程技术 • 上一篇    下一篇

一种多源安全日志融合方法的研究

王双   

  1. (taptap下载安装安卓信息安全测评中心,天津300300)
  • 收稿日期:2017-05-08 修回日期:2017-06-14 出版日期:2017-10-25 发布日期:2017-12-14
  • 作者简介:王双(1986—),女,黑龙江哈尔滨人,实习研究员,硕士,研究方向为民航信息系统、民航网络安全.
  • 基金资助:
    国家自然科学基金项目(61601467);民航安全能力建设基金(PEAS0001)

Research on multi-source security log fusion method

WANG Shuang   

  1. (Information Security Evaluation Center, CAUC, Tianjin 300300, China)
  • Received:2017-05-08 Revised:2017-06-14 Online:2017-10-25 Published:2017-12-14

摘要: 为了有效发现网络中隐藏的攻击事件,以多源日志为研究对象,提出改进加权信任度值D-S 证据理论算法来融合日志。经过数据预处理和动态自适应时间间隔阈值算法聚合生成超级告警日志,将安全设备对不同告警事件的检测率作为证据,动态修正权值并融合。实验结果与传统D-S 证据理论算法的比较结果表明,改进加权信任度值D-S 证据理论算法能够更准确地检测到网络中的攻击事件。

关键词: 多源日志, 动态自适应时间间隔阈值, D-S 证据理论, 日志融合

Abstract: In order to effectively find hidden attacks in network, taking multi-source log as research object, an improved weighted trust value D-S evidence theory is proposed to fuse logs. With data preprocessing and dynamic selfadaptive time interval threshold algorithm, super warning log is aggregated. Taking detection rates of different alarm events by safety equipment as evidence, the weights of alarm data are dynamically revised and fused.Comparison between experimental result and traditional D-S evidence theory algorithm indicates that the improved weighted trust value D-S evidence theory can improve the detection accuracy of network alarm event.

Key words: multi-source log, dynamic self-adaptive time interval threshold, D-S evidence theory, log fusion

中图分类号: 

Baidu
map