Dissertation > Excellent graduate degree dissertation topics show

Research and Implementation of Internal Network Distributed User’s Behavior Audit and Abnormal Detection System

Author: CaiQiXing
Tutor: CaiJiaZuo
School: Zhejiang University of Technology
Course: Computer Software and Theory
Keywords: internal network security behavior auditing abnormal detection event correlation mode matching
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 121
Quote: 2
Read: Download Dissertation

Abstract


As the network expending and the structure of the network becoming complicated day after day, the information security problems have became more serious. How to keep sensitive information secure has been the important issue of social, political, economic, military and other fields. In recent years, the network attacking has transformed from outside attacking to inside attacking gradually. The internal attack has the characteristics such as general, week specific, strong hidden, and it can pass the firewall and intrusion detection system easily, and it is more difficult to prevent than the attack of external network virus and hackers. The firewall, IDS can not meet these security requirements anymore. The security audit technology has made up the lack of before two greatly, and has been the important measure of the network security.This article summarized the features of the internal network user’s behavior and the abnormal behaviors, researched the correlation of user’s behavior events, and summed up two kinds of correlation between behavior events(content correlation and time serial correlation), then designed analysis arithmetic of the two kinds of correlation. Then the paper designed and implemented a internal network behavior audit system which is consist of distributed data capture module, filter module, real-time data analysis module, alarm module based on distributed structure following the standard of the TCSEC, CC and GB17859-1999. The system can capture almost kinds of the operation logs such as program execution, file reading and writing, page accessing, etc. of the user at the driver layer by HOOK mechanism. The audit data is transferred to the audit center through the network, and the analysis module analyzed the data in real-time by clustering and time serial correlation method to detect the abnormal behavior (or attack behavior) data, then alarmed.The result of the test experiment in operation system and the access control module of application system (we use ERP system) indicated that the system can monitor and record the user’s behavior effectively. The real-time analysis module can discover the abnormal operations effectively too.

Related Dissertations

  1. Research and Implementation on Technology of Network Security Events Correlation Rule’s Automatic Generation,TP393.08
  2. Fault Management Based on Event Correlation and Data Mining,TP311.13
  3. Research and Design of Network Security Event Correlation Engine,TP393.08
  4. Fault Management System Design and Implementation for Integrated Networkmanagement System,TP393.07
  5. Research and Implementation of the Security Management of 3G Mobile Network,TN929.5
  6. Network Information Audit of Key Technology Research and Implementation,TP393.08
  7. Digital Campus System of Safety Audit and Analsis,TP393.08
  8. Clustering Algorithms and Its Application in Log Data Processing,TP393.092
  9. Research and Implementation of Key Technologies in Network Security Event Management,TP393.08
  10. The Research and Implementation of Attack Model and Event Correlation Technology in Network Security,TP393.08
  11. Research on Network Fault Diagnosis and Location System Based on Correlation Technology,TP393.07
  12. Web Text Mining and Its Application in Correlation Analysis between Events,TP391.1
  13. Detection and Correlation Analysis System for Network Security Event,TP393.08
  14. CA Security Operation Management System Design and Implementation,TP393.08
  15. Event-Based Research Network Fault Management Association,TP393.07
  16. Key Technologies of Fault Detection and Event Correlation in Fault Management Systems,TP393.07
  17. Research and Implement of Enterprise Security Management Mechanism Based on Log Mining,TP393.08
  18. Rule-based multi-device alarm correlation system and its implementation,TN915.07
  19. Study of Network Event Management Based on Event Correlation,TP393.07
  20. Rule-based VoIP network event correlation and fault management technique,TN916.2

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile