论文部分内容阅读
由于缺乏评估和关联报警的背景知识,IDS(入侵检测系统)产生的海量报警无法得到更进一步的真实化确认,从而使IDS成为当今安全产品中的诟病.在事件关联范畴内的报警评估是利用被监控系统的背景知识对IDS产生的大量报警进行进一步的分析,从而把真实的危害系统的报警呈现给用户的过程.这些用于评估IDS报警的背景知识包括受害主机系统信息和网络环境信息.本文介绍了事件关联的主要结构,并着重介绍报警评估的流程和所需背景知识库;然后详细描述了基于本体的背景知识库的分类技术;最后给出基于背景知识分类技术在报警评估过程中的具体实现过程.
Due to the lack of background knowledge of assessment and correlation alarms, massive alarms generated by IDS (Intrusion Detection System) can not be further verified in real time, making IDS a criticism of today’s safety products .Alarm evaluation within the context of an incident is to utilize Background of the monitored system The process of presenting real alarms of the hazard system to the user by further analyzing a large number of alerts generated by the IDS.The background knowledge used to evaluate the IDS alert includes victim host system information and network environment information. This paper introduces the main structure of event correlation, and focuses on the process of alarm evaluation and the background of the required knowledge base; then describes in detail the classification technology based on the ontology background knowledge base; finally gives the background knowledge classification technology in the alarm evaluation process The concrete realization process.