针对网络安全态势感知的信息获取问题,设计并实现了一种面向特定服务的安全传感器.给出了基于服务指标需求的安全状态数据分类,通过对流量、性能、配置文件等数据的采集与分析处理,生成以多元组形式表示的网络安全事件,并通过安全事件之间的时序关联分析,达到对网络服务可用性与性能变化衡量的目的.实例验证结果表明,该安全传感器能够收集和处理来自特定服务的安全数据并能准确反映服务状态变化,具有较好的可行性和实用性.
Aiming at the information acquisition issues in network security situational awareness,a specific service-oriented security sensor technology was proposed,service security data were classified based on service index requirement,and detailed scheme of this security sensor was put forward.Data of flow,performance and configuration were collected and analyzed to generate network security events in the form of multi-tuple,and temporal correlation analysis was used in analyzing these events in order to reflect the variations of service availability and its performance.Case validation of DNS service data acquisition and analysis showed that this security sensor could handle the security data from specific service and reflect its situational variations well and truly.This sensor technology was also proved to be better feasibility and practicability.