DocumentCode
2663788
Title
A framework for network security situation awareness based on knowledge discovery
Author
Lan, Fang ; Chunlei, Wang ; Guoqing, Ma
Author_Institution
Dept. of Network Res., Inst. of Syst. Eng., Beijing, China
Volume
1
fYear
2010
fDate
16-18 April 2010
Abstract
Network security situation awareness provides the unique high level security view based upon the security alert events. But the complexities and diversities of security alert data on modern networks make such analysis extremely difficult. In this paper, we analyze the existing problems of network security situation awareness system and propose a framework for network security situation awareness based on knowledge discovery. The framework consists of the modeling of network security situation and the generation of network security situation. The purpose of modeling is to construct the formal model of network security situation measurement based upon the D-S evidence theory, and support the general process of fusing and analyzing security alert events collected from security situation sensors. The generation of network security situation is to extract the frequent patterns and sequential patterns from the dataset of network security situation based upon knowledge discovery method and transform these patterns to the correlation rules of network security situation, and finally to automatically generate the network security situation graph. Application of the integrated Network Security Situation Awareness system (Net-SSA) shows that the proposed framework supports for the accurate modeling and effective generation of network security situation.
Keywords
computer network security; data mining; inference mechanisms; D-S evidence theory; frequent pattern extraction; knowledge discovery; network security situation awareness; network security situation measurement formal model; Computer science; Computer security; Data engineering; Data mining; Data security; Information security; Intrusion detection; Knowledge engineering; Large scale integration; Systems engineering and theory; data mining; knowledge discovery; network security; situation awareness;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Engineering and Technology (ICCET), 2010 2nd International Conference on
Conference_Location
Chengdu
Print_ISBN
978-1-4244-6347-3
Type
conf
DOI
10.1109/ICCET.2010.5486194
Filename
5486194
Link To Document