DocumentCode
2644345
Title
A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment
Author
Xuewei, Feng ; Dongxia, Wang ; Shanwen, Ke ; Guoqing, Ma ; Jin, Li
Author_Institution
Nat. Key Lab. of Sci. & Lechnology on Inf. Syst. Security, Beijing Inst. of Syst. Eng., Beijing, China
fYear
2011
fDate
June 30 2011-July 2 2011
Firstpage
376
Lastpage
380
Abstract
After analyzing the existing research of network security situation awareness, a framework of situation analysis is proposed in this paper. It is an application and reification of the classic situation awareness model proposed by Tim bass. The framework is composed of three core contents, namely, situation information model, event correlation analysis technology and situation assessment technology. The information model defines what is situation and how to express them, the other two technologies are the implement means of acquiring these situation information. The hierarchic information model contains four levels: raw security datas, security entities, assessment report, and mission impact. Along with the rising of the model level, the quantity of the information decreases while the quality increases. The correlation technology focuses on achieving the security entities, that is the second level situation information. The situation assessment technology provides methods and means for acquiring the information belongs to the third and the fourth levels, namely, it is the technical guarantee of creating assessment report and mission impact. The framework provides guidance and technical support for the whole situation analysis procedure, and it is the foundation of the analysis work.
Keywords
computer network security; assessment report; event correlation analysis technology; mission impact; network security situation analysis; network security situation awareness; raw security datas; security entities; situation assessment technology; situation information model; Analytical models; Computational modeling; Correlation; Cyberspace; Measurement; Security; Sensors; correlation analysis; network security; situation analysis; situation assessment; situation information model;
fLanguage
English
Publisher
ieee
Conference_Titel
Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2011 Fifth International Conference on
Conference_Location
Seoul
Print_ISBN
978-1-61284-733-7
Electronic_ISBN
978-0-7695-4372-7
Type
conf
DOI
10.1109/IMIS.2011.43
Filename
5976235
Link To Document