摘要
网络安全事件在发展过程中,形成了网状的传导路径。文章提出一种基于因果关系的相似度分析方法,分析网络安全事件的传导路径。文章首先介绍了安全事件的因果关系,然后提取告警属性信息作为参数,分析其相似度并根据结果确定事件的传导路径,为进一步分析安全事件并采取相应对策提供依据。
Interact security events would form a network of propagation path in the process of development. In this paper we present a similarity analysis method based on causality, to analyze the propagation path of the security events. Firstly, we introduced the causation of the security events, then take the attribute value of the alarm information as a parameter, analyze the similarity and determine the conduction path of events according to the results, provide basis for further analysis of security event and adopt corresponding countermeasures
出处
《信息网络安全》
2013年第5期35-37,共3页
Netinfo Security
关键词
网络安全事件
因果关系
传导路径
intemet security events
causality
propagation path