Title :
A Network Security Situation Analysis framework based on information fusion
Author :
Songmei Zhang ; Shan Yao ; Xin´en Ye ; Chunhe Xia
Author_Institution :
Sch. of Comput. Sci. & Eng., Beihang Univ., Beijing, China
Abstract :
With the rapid development of the Internet, the network structure becomes larger and more complicated and attacking methods are more sophisticated, too. To enhance network security, Network Security Situation Analysis (NSSA) technology is a research hot spot in the network security domain. But at present, the NSSA framework and model which not only analyze the affected results of the network security but also the process how the network security is affected are less. In this paper, a novel NSSA framework is presented. The framework includes two parts: calculate the Network Security Situation Value (NSSV) and discover intrusion processes. NSSA quantitative assesses the impact on network security caused by attacks upon Analytical Hierarchy Process (AHP) and hierarchical network structure. Based on attack classification, intrusion processes discover the process how network security is affected. At last from the experiments results, NSSV exactly changes as attacks take place and the accurate intrusion processes are discovered. The applicability of the framework and algorithms are verified.
Keywords :
Internet; computer network security; decision making; sensor fusion; AHP; Internet; NSSA technology; NSSV; analytical hierarchy process; attack classification; hierarchical network structure; information fusion; network security situation analysis; network security situation value; Availability; Fires; IP networks; Laboratories; Optimized production technology; Security; Servers; AHP; Computer Network Defense; attak classification; network security situation Analysis;
Conference_Titel :
Information Technology and Artificial Intelligence Conference (ITAIC), 2011 6th IEEE Joint International
Conference_Location :
Chongqing
Print_ISBN :
978-1-4244-8622-9
DOI :
10.1109/ITAIC.2011.6030216