|
Network diversified , multi-service , multi-application characteristics . Single detection method and detection system is difficult to detect a variety of complex attacks , the consolidated multiple detection techniques , or a plurality of detection systems can be effectively improve the detection accuracy . However , a variety of IDS in the detection process will produce a large number of isolated , original alarm information , alarm information in addition to the mass and redundancy features , there are relatively high false negative rate and false alarm rate , makes it difficult to identify the real from attacks. So, how to solve these problems to become one of the focus of the current field of information security . Data Fusion is a multi- level , multi-faceted process of multi-source information detection, joint related , estimates and combination , in order to achieve accurate estimates and identity estimates , and complete , timely situation assessment and threat assessment . In response to the inadequacies of the existing intrusion detection system , the paper data fusion technology is applied to the intrusion detection system , designed an intrusion detection alarm data fusion model , modular approach layering process alarms from different detection agents . In this model, unified alarm detection agents local IDS alarm attribute format and eliminate duplication of alarm , and the alarm information is sent in real time to the center console ; Then using the attribute similarity algorithm fusion Alarm information in judgment between the alarm correlation when the introduction of fuzzy comprehensive evaluation method ; method based on the the attack intention of analysis and causal association , as an association rule-based fuzzy cognitive map template associated alarm information security policy , combined with the system vulnerability intrusions associated with configuration information . Finally, the model and algorithm simulation test by comparing the experimental results , the design of the alarm fusion model for effective analysis and processing of alarm information , greatly reducing the number of alarms , administrators need to be addressed to reduce the false alarm rate . Selected association method can successfully discover complex attacks , and is able to judge the consequences of the compound attack stage of the attack .
|