A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment

Innovative Mobile and Internet Services in Ubiquitous Computing(2011)

引用 2|浏览0
暂无评分
摘要
After analyzing the existing research of network security situation awareness, a framework of situation analysis is proposed in this paper. It is an application and reification of the classic situation awareness model proposed by Tim bass. The framework is composed of three core contents, namely, situation information model, event correlation analysis technology and situation assessment technology. The information model defines what is situation and how to express them, the other two technologies are the implement means of acquiring these situation information. The hierarchic information model contains four levels: raw security datas, security entities, assessment report, and mission impact. Along with the rising of the model level, the quantity of the information decreases while the quality increases. The correlation technology focuses on achieving the security entities, that is the second level situation information. The situation assessment technology provides methods and means for acquiring the information belongs to the third and the fourth levels, namely, it is the technical guarantee of creating assessment report and mission impact. The framework provides guidance and technical support for the whole situation analysis procedure, and it is the foundation of the analysis work.
更多
查看译文
关键词
correlation analysis,level situation information,situation information model,network security,assessment report,situation analysis,network security situation analysis,event correlation analysis technology,computer network security,situation assessment technology,situation information,situation assessment,whole situation analysis procedure,mission impact,event correlation,security entities,security entity,raw security datas,classic situation awareness model,network security situation awareness,correlation,sensors,measurement,computer model,information model,security,situation awareness,computational modeling,data security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要