摘要
协同式入侵监视系统实现不同管理域网络之间告警信息共享、执行集中式告警相关性分析并提供入侵预警服务而提高各个网络的安全性。介绍了设计协同式入侵监视系统面临的系统结构问题,讨论了协同式入侵监视系统的基本组成,提出了实现可扩展的安全信息交换、告警相关性分析和提高系统自身安全性问题的方法。
The collaborative intrusion monitoring system aims to improve all of the isolated network security by implementing alert sharing between these different administrative network systems,providing a centralized alert correlation and early intrusion warning services. This paper describes the architectural challenges facing the design of a collaborative intrusion monitoring system and proposes some approaches for realizing scalable security information exchanging, alert correlation and improving security of system itself.
出处
《计算机应用与软件》
CSCD
北大核心
2007年第6期159-161,共3页
Computer Applications and Software
关键词
网络安全
入侵监视
重叠网络
告警相关
Network security Intrusion monitoring Overlay network Alert correlation