• DocumentCode
    2663788
  • Title

    A framework for network security situation awareness based on knowledge discovery

  • Author

    Lan, Fang ; Chunlei, Wang ; Guoqing, Ma

  • Author_Institution
    Dept. of Network Res., Inst. of Syst. Eng., Beijing, China
  • Volume
    1
  • fYear
    2010
  • fDate
    16-18 April 2010
  • Abstract
    Network security situation awareness provides the unique high level security view based upon the security alert events. But the complexities and diversities of security alert data on modern networks make such analysis extremely difficult. In this paper, we analyze the existing problems of network security situation awareness system and propose a framework for network security situation awareness based on knowledge discovery. The framework consists of the modeling of network security situation and the generation of network security situation. The purpose of modeling is to construct the formal model of network security situation measurement based upon the D-S evidence theory, and support the general process of fusing and analyzing security alert events collected from security situation sensors. The generation of network security situation is to extract the frequent patterns and sequential patterns from the dataset of network security situation based upon knowledge discovery method and transform these patterns to the correlation rules of network security situation, and finally to automatically generate the network security situation graph. Application of the integrated Network Security Situation Awareness system (Net-SSA) shows that the proposed framework supports for the accurate modeling and effective generation of network security situation.
  • Keywords
    computer network security; data mining; inference mechanisms; D-S evidence theory; frequent pattern extraction; knowledge discovery; network security situation awareness; network security situation measurement formal model; Computer science; Computer security; Data engineering; Data mining; Data security; Information security; Intrusion detection; Knowledge engineering; Large scale integration; Systems engineering and theory; data mining; knowledge discovery; network security; situation awareness;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Engineering and Technology (ICCET), 2010 2nd International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4244-6347-3
  • Type

    conf

  • DOI
    10.1109/ICCET.2010.5486194
  • Filename
    5486194