首页> 外国专利> Log-based traceback system and method by using the centroid decomposition technique

Log-based traceback system and method by using the centroid decomposition technique

机译:质心分解技术的基于日志的回溯系统及方法

摘要

Relates to a system and method for tracking station the attacker by using the center partition (Centroid Decomposition) technique in accordance with an embodiment of the present invention, the log information input module to collect log information (log data) of the intrusion alarm from the intrusion detection system .; Applying a shortest path algorithm for the connection information of the network router collected by the network management server to generate a shortest path tree, applies a center point division techniques (centroid decomposition technique) to remove the leaf nodes of the shortest path tree to centroid node the detection, and generating a centroid tree to the detected centroid of each node as the node level centroid node detection module (centroid node); And a router connected to the source of the matching attacker to sequentially compare each level of the log information and the centroid tree of the collected intrusion alarm to request the log information of the router to be matched against nodes in each level of the centroid tree comprising: a traceback processing module traceback being, can not find the attackers to cause a security incident quickly, reducing the load on the back-trace system, threats or attacks since the vulnerability can be easy to identify through a host that exposure this corresponds to an effect of ease. ; Center split technique, intrusion detection, log-based, backtracking
机译:与根据本发明实施例的通过使用中心分区(Centroid Decomposition)技术来跟踪攻击者的系统和方法有关,日志信息输入模块用于从攻击者收集入侵警报的日志信息(日志数据)。入侵侦测系统 。;将最短路径算法应用于网络管理服务器收集的网络路由器的连接信息以生成最短路径树,应用中心点划分技术(质心分解技术)以将最短路径树的叶节点移至质心节点检测,并为检测到的每个节点的质心生成质心树作为节点级质心节点检测模块(质心节点);连接到匹配攻击者源的路由器依次比较日志信息的各个级别和收集到的入侵警报的质心树,以请求将路由器的日志信息与质心树的每个级别中的节点进行匹配,包括: :回溯处理模块回溯,无法迅速找到导致安全事件的攻击者,从而减少了回溯系统的负担,威胁或攻击,因为可以通过主机轻松识别该漏洞对应于缓解效果。 ;中心分割技术,入侵检测,基于日志的回溯

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号