摘要
针对入侵检测系统报警信息量大、琐碎和分散的问题,提出了一种基于不确定性知识发现的入侵报警关联方法。该方法的知识发现部分采用提出的不确定性序列模式发现算法CWINEPI对报警数据进行序列模式发现,并转化成入侵报警精简规则;再对入侵报警序列模式进行关联以获取攻击模式,并转化为入侵场景重建规则。入侵报警关联部分使用报警关联引擎,对多个入侵检测系统上报的入侵报警进行关联。通过DARPA2000的报警数据验证了知识发现部分的良好性能,测试环境中的入侵报警的关联结果表明了该方法是高效、可行的。
To solve the problems of large quantity,trivialness and dispersion of intrusion alerts in intrusion detection systems,an intrusion alert correlation method based on uncertain knowledge discovery was proposed.In the knowledge discovery part,a new discovery algorithm of uncertain sequence patterns,named CWINEPI,was used to discover the sequence patterns of intrusion alerts and translated them into intrusion alerts condensed rules.The attack patterns were obtained with correlating sequence patterns,and convert...
出处
《计算机应用》
CSCD
北大核心
2009年第3期808-812,共5页
journal of Computer Applications
基金
国防基础科研项目(A3220061163)
关键词
入侵检测
知识发现
报警关联
intrusion detection
knowledge discovery
intrusion alert correlation