提出一种基于MLP网络的主动报警关联技术,这种技术不依赖于已有专家报警知识,经过初始的训练,能自动识别攻击场景,使初始报警自动关联。通过用MLP网络计算报警之间的关联概率,构建实时报警图;用遗传算法优化MLP网络;用关联矩阵存储报警之间的关联信息;用不断更新的关联矩阵来构建相应攻击策略图;描述了报警关联实时报警图和攻击策略图的构建过程;实验验证效果良好。
This article proposed one kind based on the MLP network alarm correlation technique, this technique does not rely on existing expert alarm knowledge, after initial training, can automatically identify the attack scenarios, the initial alarm correlation. By using MLP network to calculate the correlation between construction of alarm probability, real-time alarm graph; genetic algorithm optimization MLP neural network; correlation matrix storage alarm correlation between information; with continuous updating of the incidence matrix to construct the corresponding strategy of attack graph; describe the alarm correlation real alarm graph and attack strategy of construction process; experimental verification the effect of good.