首页> 外文会议>Applied Machine Intelligence and Informatics (SAMI), 2012 IEEE 10th International Symposium on >A new adaptive evidential reasoning approach for network alarm correlation
【24h】

A new adaptive evidential reasoning approach for network alarm correlation

机译:网络警报关联的自适应证据推理新方法

获取原文
获取原文并翻译 | 示例

摘要

In computer networks, fault detection and identification techniques rely substantially on analyzing a set of observed alarms generated by different network entities due to unknown failures. However, network alarms are subject to becoming lost and spurious and their information is often incomplete, ambiguous, and inconsistent. In this paper, an adaptive distributed Dempster-Shafer evidential reasoning technique is proposed to effectively reduce the negative impact of the uncertainty properties which network alarms can exhibit. Each observed alarm is perceived as a piece of evidence and as such, the incomplete and ambiguous properties can be tackled within the framework of the evidential theory. A discounting mechanism by which the observed alarms are assigned certain weights is also presented. A given weight reflects the significance of the information in the corresponding alarm. Then, the alarms are correlated by the Dempster's rule of combination and the inconsistent alarms play a limited role in the alarm correlation process since they are given lower weights. Simulations confirm that the proposed scheme has a high detection rate even in the presence of defective alarms.
机译:在计算机网络中,故障检测和识别技术基本上依赖于分析由于未知故障而由不同网络实体生成的一组观察到的警报。但是,网络警报容易丢失和虚假,其信息通常不完整,模棱两可和不一致。本文提出了一种自适应的分布式Dempster-Shafer证据推理技术,以有效减少网络警报可能表现出的不确定性的负面影响。每个观察到的警报都被视为证据,因此,不完整和模棱两可的属性可以在证据理论的框架内解决。还提出了一种折现机制,通过该机制可以为观察到的警报分配特定的权重。给定的权重反映了相应警报中信息的重要性。然后,通过Dempster组合规则将警报关联起来,并且由于警报的权重较低,不一致的警报在警报关联过程中的作用有限。仿真证实,即使在存在缺陷警报的情况下,所提出的方案也具有较高的检测率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号