跳到主要导航 跳到搜索 跳到主要内容

Network security situation assessment based on data fusion

  • Lanzhou University of Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

10 引用 (Scopus)

摘要

Network security situation assessment can project the next behavior of the network by describing the current state. Security events from IDS, firewall, and other security tools are currently growing at a rapid pace. However, most intrusion event researches focus on IDS alerts, overlooking other intrusion evidence from other security tools, or they make simple integration of various security tools not inflecting the whole network state. In this paper, we described network security from the view of system. First, network situation elements are analyzed. Second, we research their correlations and present system architecture of network security situation. Third, multi-sensor correlation algorithms are analyzed that Colored Petri net is used for describing the changing of system state after arrival of new events and D-S Theory of Evidence is used for combining the different evidence. Then, we report the experimental results on the DARPA 2000 DDoS attack scenarios and analyze them. At last, we conclude our work and present next research goal.

源语言英语
主期刊名Proceedings - 1st International Workshop on Knowledge Discovery and Data Mining, WKDD
542-545
页数4
DOI
出版状态已出版 - 2008
已对外发布
活动1st International Workshop on Knowledge Discovery and Data Mining, WKDD - Adelaide, 澳大利亚
期限: 23 1月 200824 1月 2008

出版系列

姓名Proceedings - 1st International Workshop on Knowledge Discovery and Data Mining, WKDD

会议

会议1st International Workshop on Knowledge Discovery and Data Mining, WKDD
国家/地区澳大利亚
Adelaide
时期23/01/0824/01/08

学术指纹

探究 'Network security situation assessment based on data fusion' 的科研主题。它们共同构成独一无二的学术指纹。

引用此