首页> 外文会议>International Conference on Advances in Computing and Communications >Preprocessor for Complex Event Processing System in Network Security
【24h】

Preprocessor for Complex Event Processing System in Network Security

机译:网络安全中复杂事件处理系统的预处理器

获取原文

摘要

Network security refers to any activity designed to protect the network. These activities intend to protect the usability, reliability, and safety of network and data. Effective network security targets a variety of threats and stops them from entering or spreading on network. In network security, Complex Event Processing (CEP) system can be used for correlating events across different security devices and applications for complicated attack detection and response. The events will be recorded in sys log files. There will be millions of events generated by each security device. Hence, the CEP engine has to process massive amount of logs. We describe a method for pre-processing the vast input to extract relevant data, the CEP engine shall be concerned about. The CEP engine which we used in this system is ESPER. The sys log is preprocessed based on risk taxonomy. Risk taxonomy is built in a hierarchical structure with respect to the attacks the CEP is looking for.
机译:网络安全是指旨在保护网络的任何活动。这些活动旨在保护网络和数据的可用性,可靠性和安全性。有效的网络安全性可针对各种威胁,并阻止它们进入网络或在网络中传播。在网络安全中,复杂事件处理(CEP)系统可用于关联不同安全设备和应用程序之间的事件,以进行复杂的攻击检测和响应。这些事件将记录在sys日志文件中。每个安全设备都会生成数百万个事件。因此,CEP引擎必须处理大量日志。我们描述了一种预处理大量输入以提取相关数据的方法,CEP引擎应予以关注。我们在此系统中使用的CEP引擎是ESPER。系统日志是根据风险分类法进行预处理的。风险分类法是针对CEP正在寻找的攻击以分层结构构建的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号