摘要
网络集中安全审计系统的研究与应用已经成为国内外研究的热点。在海量的网络事件中,准确实时地检测分析入侵安全事件的类别并自动响应是集中审计系统实现中关键的技术,也是最大的难点。本文研究了基于状态机的实时关联分析子系统的实现技术,其中详细分析了攻击场景描述、场景库和分析引擎的实现方法。
The research and application of network concentration security audit system is becoming the focus of world. It is pivotal and difficult to accurately and timely detect the categories of intrusion events, This paper mainly researches the design and realization of real time association analyzing subsystem based on state machine, analyses the description of attack scene and the realization of scene database and analysis engine in detail.
出处
《计算机与现代化》
2006年第6期94-96,109,共4页
Computer and Modernization
关键词
审计系统
关联分析
状态机
场景库
实时
audlt system
association analyzing
state machine
scene database
real-time