DocumentCode :
2644345
Title :
A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment
Author :
Xuewei, Feng ; Dongxia, Wang ; Shanwen, Ke ; Guoqing, Ma ; Jin, Li
Author_Institution :
Nat. Key Lab. of Sci. & Lechnology on Inf. Syst. Security, Beijing Inst. of Syst. Eng., Beijing, China
fYear :
2011
fDate :
June 30 2011-July 2 2011
Firstpage :
376
Lastpage :
380
Abstract :
After analyzing the existing research of network security situation awareness, a framework of situation analysis is proposed in this paper. It is an application and reification of the classic situation awareness model proposed by Tim bass. The framework is composed of three core contents, namely, situation information model, event correlation analysis technology and situation assessment technology. The information model defines what is situation and how to express them, the other two technologies are the implement means of acquiring these situation information. The hierarchic information model contains four levels: raw security datas, security entities, assessment report, and mission impact. Along with the rising of the model level, the quantity of the information decreases while the quality increases. The correlation technology focuses on achieving the security entities, that is the second level situation information. The situation assessment technology provides methods and means for acquiring the information belongs to the third and the fourth levels, namely, it is the technical guarantee of creating assessment report and mission impact. The framework provides guidance and technical support for the whole situation analysis procedure, and it is the foundation of the analysis work.
Keywords :
computer network security; assessment report; event correlation analysis technology; mission impact; network security situation analysis; network security situation awareness; raw security datas; security entities; situation assessment technology; situation information model; Analytical models; Computational modeling; Correlation; Cyberspace; Measurement; Security; Sensors; correlation analysis; network security; situation analysis; situation assessment; situation information model;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2011 Fifth International Conference on
Conference_Location :
Seoul
Print_ISBN :
978-1-61284-733-7
Electronic_ISBN :
978-0-7695-4372-7
Type :
conf
DOI :
10.1109/IMIS.2011.43
Filename :
5976235
Link To Document :
بازگشت