Dissertation > Excellent graduate degree dissertation topics show

Research and Design on an Alerts Merge Schme in Network Security Management System

Author: ZuoBin
Tutor: ZhangRu
School: Beijing University of Posts and Telecommunications
Course: Information Security
Keywords: network security management IDS FSM Bayesian network alert merge
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 53
Quote: 1
Read: Download Dissertation

Abstract


Along with the spread of internet, the amount of network attack and illegal access is growing rapidly. The situation of network security is harder and harder day by day. In order to guarantee the security of intranet, the security governors build a defense system including firewall, anti-virus server, IDS, etc. These security devices reports large amounts of alerts. The features of these alerts include huge amount, high rate of mistakes, trivial information, hard to analysis and understand, etc. These alerts have bad influence on the analysis and handling of attacks and take lots of time of security governors. The duplicate alerts, fake alert and meaningless alerts bring many difficulties to the network security management witch nearly over the limit of human ability.In this situation, to efficient handling alert information, alert merge technology gets more and more attentions. Alert merge technology include combine duplicate alerts, filter the meaningless and fake alerts, associate fragmented alerts, define the risk level. The purpose of alert merge is enhancing alert information and accuracy, decrease alert amount. Researchers home and abroad are conducting extensive research and have achieved certain results recently. Methods based on probability theory can’t reveal the relation between alerts, and is hard to find out priori probability. Methods based on state transition need to associate every kind of alerts, and bring large amount of workload. Methods based on Euclidean distance are hard to define threshold.Method proposed in this paper which includes categories alerts, then calculate the probabilities of every kind of alert and other data, merge alert based on FSM, at last build a Bayesian network according to the state of FSM and alerts probabilities, calculate reliability of merged alert, solve some problems in the alert merge system, and has the ability to learn new attacks.Chapter 1 introduced the developing of internet and network security situation in China. Chapter 2 introduced IDS technology and the developing of alert merge. Chapter 3 proposed an alert merge scheme based on FSM. Chapter 4 proposed a method of calculating alert reliability based on Bayesian network, and made lots of discussion on time window, alert probability, posterior probability, building Bayesian network according to attack scene. Chapter 5 implement the scheme in a network security management system and did some analysis. Chapter 6 summarized and forecasted the developing of alert merge technology.

Related Dissertations

  1. Multi-Sensor Information Fusion and Its Applications on Wearable Computer,TP202
  2. Research on Air Target Intention Recongniton Based on Multi-entities Bayesian Network,E072
  3. Intranet IPv6 Transition Network Integration Platform,TP393.04
  4. Research and Implement of Intrusion Detection System Based on P2P and Mobile Agent,TP393.08
  5. A Study on Firewall and IDS Linkage Algorithm,TP393.08
  6. Research on Runtime Verification for Software Behavior,TP311.52
  7. Based on Bayesian Classification Applied Research in Higher Vocational Teaching Software,TP311.5-4
  8. An Expectation Maximization Application for Decision Tree Classifiers on Datasets with Missing Values,TP311.13
  9. Bluetooth Hands Free Profile Implement Research,TN925
  10. Merging Multiple Microarry Datasets to Build Gene Regulatory Networks,Q811.4
  11. The Bayesian Network in the Agricultural Experts Within Application Systems Research,S126
  12. On Defense-in-Depth Strategy and Infrastructure Management of Campus Network,TP393.18
  13. Research and Implementation of Honeypot Based on Redirection Mechanism,TP393.08
  14. Research on Intrusion Control and Audit Expert System,TP393.08
  15. Intrusion Detection System (IDS): Simulation and Analysis of Denial of Service Attacks,TP393.08
  16. The Research of the BMHS2 Algorithm and Its Application in IDS,TP393.08
  17. China corporate information security program design,TP393.08
  18. Design and Implementation,TP393.08
  19. Design and Implementation of a FSM Generator Applied to Protocol Stack Development,TP311.52
  20. Event Detection Modeling and Optimization in Intelligent Video Surveillance,TP391.41
  21. Research and Implementation of Parser Based on SMIL,TN919.8

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile