摘要
用户的网络管理需要建立一种新型的综合网络安全管理解决方案,即统一网络安全管理。关注其中的一个关键功能——协同报警分析,在把握现有研究方向的基础上,提出一个网络安全报警分析基本框架。现今存在的主要问题在于如何保证安全报警的环境资产信息、背景知识与攻击知识的统一表达。目前,针对这一问题仍缺乏一个实践可行的有效方法,这将直接影响到统一网络安全管理的最终实现。在协同报警分析过程中引入CIM模式扩展的OWL+SWRL安全本体来统一表达信息与知识,并提出一个极具潜力的方法用以完善现有协同报警分析技术,作为实现统一网络安全管理的重要步骤。
Network users need a new integrated solution for network security management, or in other words, unified network security management. This paper discussed collaborative alert analysis, which is one of its key functionalities, and based on a sufficient understanding of research direction,a basic network security alert analysis model was then provided. As for collaborative alert analysis, the main problem is how to guarantee unified representation of context information, background knowledge and attack knowledge for security alerts. And the fact is that, a practical and efficient app- roach is still lacking these days,which influents the realization of unified network security management. This paper introduced the use of security ontology by means of OWL+SWRL based on CIM Schema for unified representation of information and knowledge, and aimed at proposing a promising approach to improve existing collaborative alert analysis techniques as an important stage to realize unified network security management.
出处
《计算机科学》
CSCD
北大核心
2009年第5期104-107,157,共5页
Computer Science
基金
湖北省科技攻关重大项目(2004AA103A01)
武汉市科技攻关计划项目(200710421130)资助
关键词
网络安全
报警分析
协同
安全本体
Network security,Alert analysis,Collaboration,Security ontology