浏览全部资源
扫码关注微信
1. 哈尔滨工程大学计算机科学与技术学院
2. 哈尔滨工程大学计算机科学与技术学院,黑龙江,哈尔滨,150001
纸质出版日期:2006-05-01,
移动端阅览
[1]冯光升,王慧强,武俊鹏,赵倩.一种新的基于分布式入侵检测的警报聚类方法[J].武汉大学学报(理学版),2006(05):635-638.
FENG GUANGSHENG, WANG HUIQIANG, WU JUNPENG, et al. A Novel Method of Alarm Clustering Based Distributed Intrusion Detection. [J]. 2006, (5): 635-638.
[1]冯光升,王慧强,武俊鹏,赵倩.一种新的基于分布式入侵检测的警报聚类方法[J].武汉大学学报(理学版),2006(05):635-638. DOI:
FENG GUANGSHENG, WANG HUIQIANG, WU JUNPENG, et al. A Novel Method of Alarm Clustering Based Distributed Intrusion Detection. [J]. 2006, (5): 635-638. DOI:
针对大量的异构入侵检测传感器产生的警报泛滥问题
提出了一种在线警报聚类融合模型.该模型根据自我学习和调节
建立元警报作为警报聚类融合的基础
对新产生的警报进行分类、聚类
最终将警报特征与元警报融合
扩充元警报的特征信息.实验结果表明该方法能够有效地减少警报数量
提供具有指导意义的入侵响应
并且聚类结果可被用来进行进一步的网络态势评估.
In respect to the issue of alarms flooding
which is resulted from multiple detection sensors in terms of intrusions
this article proposes a novel on-line model on alarms clustering and fusion.Based upon self-learning
adjustment
and establishment of meta-alarms by clustering and fusing
this new model will classify
cluster and eventually fuse the new alarm with an existing meta-alarm.Through experiment
the result shows that this emerging model has some significant improvements.For instance
it can dramatically decrease the quantity of alarms and provide the instructive signals on intrusion respondence.Moreover
the result of clustering can be utilized in the further evaluation on threat analysis.
网络安全分布式入侵检测系统警报聚类
network securitydistributed intrusion detection systemalarm clustering
0
浏览量
154
下载量
7
CSCD
关联资源
相关文章
相关作者
相关机构