• DocumentCode
    2644345
  • Title

    A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment

  • Author

    Xuewei, Feng ; Dongxia, Wang ; Shanwen, Ke ; Guoqing, Ma ; Jin, Li

  • Author_Institution
    Nat. Key Lab. of Sci. & Lechnology on Inf. Syst. Security, Beijing Inst. of Syst. Eng., Beijing, China
  • fYear
    2011
  • fDate
    June 30 2011-July 2 2011
  • Firstpage
    376
  • Lastpage
    380
  • Abstract
    After analyzing the existing research of network security situation awareness, a framework of situation analysis is proposed in this paper. It is an application and reification of the classic situation awareness model proposed by Tim bass. The framework is composed of three core contents, namely, situation information model, event correlation analysis technology and situation assessment technology. The information model defines what is situation and how to express them, the other two technologies are the implement means of acquiring these situation information. The hierarchic information model contains four levels: raw security datas, security entities, assessment report, and mission impact. Along with the rising of the model level, the quantity of the information decreases while the quality increases. The correlation technology focuses on achieving the security entities, that is the second level situation information. The situation assessment technology provides methods and means for acquiring the information belongs to the third and the fourth levels, namely, it is the technical guarantee of creating assessment report and mission impact. The framework provides guidance and technical support for the whole situation analysis procedure, and it is the foundation of the analysis work.
  • Keywords
    computer network security; assessment report; event correlation analysis technology; mission impact; network security situation analysis; network security situation awareness; raw security datas; security entities; situation assessment technology; situation information model; Analytical models; Computational modeling; Correlation; Cyberspace; Measurement; Security; Sensors; correlation analysis; network security; situation analysis; situation assessment; situation information model;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2011 Fifth International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-61284-733-7
  • Electronic_ISBN
    978-0-7695-4372-7
  • Type

    conf

  • DOI
    10.1109/IMIS.2011.43
  • Filename
    5976235