Dissertation > Excellent graduate degree dissertation topics show
The Research and Implementation of Attack Model and Event Correlation Technology in Network Security
Author: LiuXueJiao
Tutor: XiaoDeBao
School: Central China Normal University
Course: Applied Computer Technology
Keywords: Network Security Management Attack Knowledge Model Event correlation analysis Verification Scene
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 224
Quote: 2
Read: Download Dissertation
Abstract
|
With the gradual improvement of the rapid development of the network as well as the degree of social information, network security issues showing diversified and complicated trend to large-scale attack activities, collaborative and multi-level direction. People constantly firewall, intrusion detection systems, vulnerability scanning tools and other safety equipment to monitor the network in order to resist the invasion. Of course, these products, respectively, on different sides protected network system. However, relatively independent of the deployment of a variety of safety equipment to produce a massive event alarm, which flooded with a large number of repeat and unreliable information, thus creating even alarm flooding \aggressive behavior, lack of effective integration and association allows the administrator is difficult to identify a potential threat to to grasp global security situation. Widely used for multi-source heterogeneous security devices in the network security events generated by the current situation is difficult to effectively manage, unified network security management has been proposed and become a research focus of concern in the field of network security management. Unified network security management platform is a set of multi-source data collection, and the unified alarm assessment and event correlation analysis for the integration of security information and event management platform. As the core of the event correlation analysis, a description of attack, attack validation, attack detection, attack correlation, attack attack reaction Knowledge Base is essential. It is information sharing and security event correlation analysis of various data sources to provide the protection of knowledge, and a direct impact on the final results of the event correlation analysis. However, the network security attack model is still a lack of effective solutions. This article uses the security events to abstract and describe aggressive behavior to eliminate the drawbacks of low level coarse-grained alarm information to achieve more accurate complex attacks, comprehensive description; design a hierarchical XML-based association rules, and to ensure that its usefulness can be reusability and scalability; intrusion detection based on validated from a large number of security incidents in the accurate identification of a real intrusion has phase characteristics, use the scene of the attack-oriented reasoning; multi-step attack, construct attack scenarios grasp the overall security posture of the network; addition, through the reconstruction of the attack trajectory chain, and further found that the intrinsic link between the attacks, identify intrusion attempts and predict the next step attacks. Finally, in a lab environment to build management platform, using Netpoke replay DARPA data set, and verify the feasibility and effectiveness of the proposed attack model and event correlation technology.
|
Related Dissertations
- On the Reproduction of "Beauty in Scenery Description" in Translation of Lierary Works,I046
- Sandstorm scene parametric modeling and rendering research,P445.4
- Research on Optimal Design of Marine Enclosed Epicyclic Gear,U664.22
- Structural-design, Emulation and Validation of Broadband Wave-transparent Ceramic Matrix Composite Sandwich,TB332
- Research on Error of Highly Precise Orientation Survey with Gyrotheodolite and Its Calibration,P204
- Advanced EFA electrical failure analysis the positioning technology PFA physical verification technology research,TN407
- The production-proven 45nm NOR Flash,TP333
- Power PC front-end design and implementation of verification,TP368.1
- Visual Simulation of Branch Breaking,TP391.41
- Research of Secure Processor Architecture Based on Stream Cipher,TP309
- Research and Implementation on Dynamic Scene Stitching,TP391.41
- Trains visual simulation middle three-dimensional modeling technology research,TP391.9
- Interface Automata Based Verification of Web Service Composition,TP393.09
- Dimensionality reduction and control of spectral method based on the rigid-flexible manipulator model,TP241
- China's stock public offering and listing of auditing system,F832.51
- Construction Differentially Expressed Genes of Fear Memory of Adult Rats with Maternal Separation,R749.5
- Design and Implementation of Mining Rights Management Information System Based on Component Technology,P237
- Virtual showcase for indoor three-dimensional scene quickly build and optimization technology research,TP391.41
- Feature-based scenario simulator performance testing of virtual machines,TP302
- SystemVerilog-based functional verification module URAT,TN402
- Bayes test equipment based on the loss of statistical reliability of the design verification test,TJ06
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|