计算机应用研究2009,Vol.26Issue(8):2995-2999,5.DOI:10.3969/j.issn.1001-3695.2009.08.057
入侵检测系统中分层报警处理模型的研究
Research on hierarchical alarm processing model in intrusion detection system
摘要
Abstract
In view of the alarm flooding problem, this paper studied a hierarchical alarm processing model to filter, reduce, fuse and correlate alarm data. In filtering, eliminated false alarms with repository. In reduction, designed a reduction algorithm to remove the duplicate alarms in real time. In fusion, proposed a clustering-based fusion algorithm to banish similar alarms in real time. In correlation, implemented the frequent episodes algorithm on training data to find the intrusion patterns and constructed repository which provided similarity to the clustering-based correlation algorithm. Through the above processing, eliminated the false and invalid alarms, which eased the networks system and administrator's burden. Meanwhile, found the intrusion patterns and reported the alarm prediction. Experimental results show the model is effective.关键词
入侵检测/报警处理/聚类算法Key words
intrusion detection/alarm processing/clustering algorithm分类
信息技术与安全科学引用本文复制引用
肖立中,刘云翔,戴蒙..入侵检测系统中分层报警处理模型的研究[J].计算机应用研究,2009,26(8):2995-2999,5.基金项目
上海高校选拔培养优秀青年教师科研专项基金资助项目(YYY-07008) (YYY-07008)
上海应用技术学院引进人才科研启动资助项目(YJ2007-24) (YJ2007-24)
上海应用技术学院计算机科学与技术重点学科资助项目 ()