针对网络安全事件流中异常检测问题,定义网络安全异常事件模式为候选频繁情节,基于无折叠出现的频繁度定义研究网络安全事件流中频繁情节发现方法。该方法中,针对事件流的特点,提出了频繁度密度概念;针对网络安全异常事件模式的时间间隔限制,利用事件流中滑动窗口设计算法;针对复合攻击模式的特点,对算法进行剪枝。实验证明本文方法的时空复杂性、漏报率符合网络安全事件流中异常检测的需求。
Anomalous patterns of network security events were defmed as episodes to serach episodes in network security event streams based on frequency definition of non-overlapped occurrences. First, density of frequency was defined for characteristic of event streams.Then,for time interval constrain of anomalous patterns in network security event streams, sliding window was used. Finaly, pruning algorithm was proposed for multi-step attacks. Experiment results prove that this method is efficient and has low false negative rate for anomaly detection in network security event streams.