位置:成果数据库 > 期刊 > 期刊详情页
针对隐含约束条件的报警关联判别算法
  • ISSN号:1000-1239
  • 期刊名称:《计算机研究与发展》
  • 时间:0
  • 分类:TP393.08[自动化与计算机技术—计算机应用技术;自动化与计算机技术—计算机科学与技术]
  • 作者机构:[1]中国科学院研究生院信息安全国家重点实验室,北京100049
  • 相关基金:In recent years, alert correlation, as the high level analyzer for alert generators (IDS, anti-virus, firewall, and so forth), has become more and more necessary to the network security management. In this paper, the CDAIR algorithm is given to correlate the alerts, between them hiding the implied restriction, especially for the time restriction, the location restriction and the access control restriction. Therefore, the correlation using the CDAIR algorithm is more precise and effective. Our work is supported by the National Natural Science Foundation of China (60403006) and the National Grand Fundamental Research 973 Program of China (G1999035801).国家自然科学基金项目(60403006);国家“九七三”重点基础研究发展规划基金项目(G1999035801)
中文摘要:

因果关联法是当前报警关联所普遍采用的方法之一,这种方法的基础在于判断两条报警之间的关联性.然而。此项研究所面对的一个重要问题是判别报警之间的间接联系.因此,首先对报警关联的一般方法进行形式化描述,以此阐述传统的因果关联算法存在的局限性,并分析存在隐含约束关系时关联的难点所在,讨论各种隐含约束关系的存在形式,最终提出针对隐含约束关系的报警关联判别算法(CDAIR),特别是针对时间约束、定位约束和访问控制约束的判别方法.对该算法给出了相应实验的实验过程以及实验结果,证实了算法的有效性.

英文摘要:

With the development of the network in the scale and the bandwidth, security issues have become more and more complex and the requirement for correlation technology is rapidly increased. The causal correlation is one of the most popular correlation methods, whose basis is the judgment method for relation between two alerts. In this paper, a formal description for general causal correlation is given, which presents some limitations in the conventional approaches. Then the difficulty in correlation with implied restriction is analyzed, and some cases about this restriction and solutions are discussed. Sometimes an alert occurs for the duration of time, therefore how to distinguish the order for two alerts becomes mysterious, which is the problem about time restriction. In real world one host may have several interfaces, while an interface may have several addresses, and which type of problems may result in the location restriction. In the whole history of the modern OS, the issue of the access control is an important role, and the complex relation during subject, object and privilege is the most difficult part for correlation of two alerts, which involves access control restriction. Finally, a new correlation determine algorithm for implied restriction (CDAIR) is proposed, which solves these problems for the time restriction, the location restriction and the access control restriction. Also given are the process and the result of the corresponding experiment which proves the validity of the algorithm.

同期刊论文项目
期刊论文 24 会议论文 2
同项目期刊论文
期刊信息
  • 《计算机研究与发展》
  • 中国科技核心期刊
  • 主管单位:中国科学院
  • 主办单位:中国科学院计算技术研究所
  • 主编:徐志伟
  • 地址:北京市科学院南路6号中科院计算所
  • 邮编:100190
  • 邮箱:crad@ict.ac.cn
  • 电话:010-62620696 62600350
  • 国际标准刊号:ISSN:1000-1239
  • 国内统一刊号:ISSN:11-1777/TP
  • 邮发代号:2-654
  • 获奖情况:
  • 2001-2007百种中国杰出学术期刊,2008中国精品科...,中国期刊方阵“双效”期刊
  • 国内外数据库收录:
  • 俄罗斯文摘杂志,荷兰文摘与引文数据库,美国工程索引,日本日本科学技术振兴机构数据库,中国中国科技核心期刊,中国北大核心期刊(2004版),中国北大核心期刊(2008版),中国北大核心期刊(2011版),中国北大核心期刊(2014版),中国北大核心期刊(2000版)
  • 被引量:40349