首页> 外文会议>2011 Fifth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing >A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment
【24h】

A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment

机译:基于事件关联和态势评估技术的网络安全态势分析框架

获取原文

摘要

After analyzing the existing research of network security situation awareness, a framework of situation analysis is proposed in this paper. It is an application and reification of the classic situation awareness model proposed by Tim bass. The framework is composed of three core contents, namely, situation information model, event correlation analysis technology and situation assessment technology. The information model defines what is situation and how to express them, the other two technologies are the implement means of acquiring these situation information. The hierarchic information model contains four levels: raw security datas, security entities, assessment report, and mission impact. Along with the rising of the model level, the quantity of the information decreases while the quality increases. The correlation technology focuses on achieving the security entities, that is the second level situation information. The situation assessment technology provides methods and means for acquiring the information belongs to the third and the fourth levels, namely, it is the technical guarantee of creating assessment report and mission impact. The framework provides guidance and technical support for the whole situation analysis procedure, and it is the foundation of the analysis work.
机译:在分析了现有网络安全态势感知研究的基础上,提出了一种态势分析框架。它是蒂姆·贝斯(Tim bass)提出的经典态势感知模型的应用和改进。该框架由三个核心内容组成,即情境信息模型,事件关联分析技术和情境评估技术。信息模型定义了什么是情境以及如何表达情境,另外两种技术是获取这些情境信息的实现手段。分层信息模型包含四个级别:原始安全数据,安全实体,评估报告和任务影响。随着模型级别的提高,信息量减少,而质量增加。关联技术侧重于实现安全实体,即第二级情况信息。态势评估技术提供了获取信息的方法和手段,属于第三,四级,是创建评估报告和任务影响的技术保证。该框架为整个情况分析过程提供了指导和技术支持,是分析工作的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号