|
The computer network is widely used in various industries , network security has also become increasingly concerned about the problems of institutions and enterprises . Although the system of firewalls , anti-virus , IDS , vulnerability scanning and other security products have been deployed in the network , but the lack of effective integration of a variety of safety equipment , in the face of its massive log information , network managers are often difficult to cope with network security threats remain . Originally isolated safety equipment to form a unified whole , a coordinated response to a variety of security information event , we asked the research and development of unified network security management platform , it is a comprehensive network security solutions programs. Log and alarm information , unified network security management platform through its various data collection Agent to collect and analyze the safety equipment in the control center network systems are protected the whole alarm analysis, risk assessment , ensure security incidents timely response and processing. Which , from a variety of safety equipment efficiency, flexibility to collect log data is important to a unified network security management . However, due to the wide range of sources of log data , the format is different , the amount of data , which gave the log collection work caused considerable difficulty . Thus , this paper presents a distributed data acquisition agent framework , it can effectively solve the problem of the platform log collection , but can be applied to a variety of different structures , different scale network environment . In this paper, on the basis of the overall analysis of unified network security management platform , research data collection of plug-in technology , the type of event , combined with Agent technology is designed and implemented data collection Agent model . Data acquisition based Agent model , this paper further study to design a multi-level fusion events in the frame structure and the hierarchical structure of distributed log data collection agent communication mechanism between components . The distributed data acquisition agent framework can be applied to a different scale network environment , with a wide range of flexible and scalable , powerful real-time monitoring capabilities , event multi - level fusion mechanism , safe , and efficient data communication .
|