Dissertation > Excellent graduate degree dissertation topics show
Research on a Rule-Based Approach to Network Security Event Correlation
Author: PanAnQun
Tutor: LiZhiTang
School: Huazhong University of Science and Technology
Course: Computer System Architecture
Keywords: Network Security Correlation Analysis Rule based tree Similarity Reliability
CLC: TP393.08
Type: Master's thesis
Year: 2007
Downloads: 232
Quote: 3
Read: Download Dissertation
Abstract
|
With speed development of complicated covert distributed attack methods and technologies, the network security management faces three major issues: the huge amount of security alert data, redundancy and false positives. It’s impossible to analyse and manage these data manually. Only the network security event correlation analysis can correlate these data, and mine the essential relationships between alerts, and discover the latent attack intentions effectively and timely, then takc preventive measures, to ensre netork security.The rule-based approach to network security event correlation aggregates alerts through the similarity between those alerts, and eliminates false alerts by reliability scores of the alerts. Meanwhile the relation between nodes in tree-rules is used to correlate the scattered alerts to an attack scenario.The similarity between alerts is fixed on the feature similarity: these is a similarity function for each difference feature: for attack class similarity we maintain a matrix of similairty between attack classes, and IP address similarity is decided by the maximum number of 1 bits in an IPv4 subnet mask that could account for the two addresses. Only every feature threshold is exceeded , the alerts are similar and can be aggregated.Directives based tree-rule are created for each attack scenarios: the root node represent the beginning of attack, and the leaf is the end; the parent node is the premise of child node, and each child node express a trend of the attack. The more deeply directives match the alerts, the attack is more likely to succeed.The reliability of alerts depends on two factors: the first is the amount of alerts aggregated, the more alerts aggregated, the more credible; The second is the depth of directives matched, the triggering of each step shows that the attackers has reached the previous step, and may take the further attacks, and the reliability should be increased.The experiments show that the algorithm offers excellent performance in alert reduction and attack false negative rate, and is effective to reduce the amount of alerts and false positives, and correlate the alerts.
|
Related Dissertations
- Syntactic Features Based Pronoun Resolution,TP391.1
- The Research of Malware Detection Technology Based on Active Mode,TP393.08
- Research of IRC Botnet Detection Based on Behavior,TP393.08
- Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
- Evaluation of Photosynthetic Efficiancy of Seedlings of the Hybrid Progenies (F1) in Peach,S662.1
- The Research and Application of Software Reliability Test for User Right Management System,TP311.53
- Research on Subsea Pipeline Repair Coupling,TE973
- Study on Photosynthetic Characteristics of Peach Based on Heterosis of Assimilation Capacity,S662.1
- Research and Application on Reliability Technology of Mine Hidrological Monitoring System,TD742.1
- Ontology -based Semantic Web service matching and composition method,TP393.09
- WordNet and the \,G254
- Amendment of Mental Health Evaluation Scale for Chinese Nuclear Power Plant Operators,B849
- Research of Text Clustering on Food Complaint Documents Based on Ontology,TP391.1
- One based on pattern matching lightweight network intrusion detection system design and implementation,TP393.08
- Study on the Algorithm of Cranio-facial Reconstruction,TP391.41
- Analysis on DDoS Attacks Detecting Technology Based on Eigenvector,TP393.08
- Harmonious Society under the Network Security Problems and Countermeasures,TP393.08
- Network Security Incident Analysis and Implementation Strategies,TP393.08
- The Research of Attack Source Traceback in Distributed Denial-of-Service Attacks Based on VoIP,TP393.08
- Ship mountain of e-government network security solutions outside the network design and implementation,TP393.08
- Research on Streaming Media Detection Methods Against DoS\DDoS Attack Based on Analysis of Self-similarity,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|