版权说明 操作指南
首页 > 成果 > 详情

An Alert Correlation Method Based on Improved Cluster Algorithm

认领
导出
反馈
分享
QQ微信 微博
成果类型:
会议论文
作者:
Peng, Xi*;Zhang, Yugang;Xiao, Shisong;Wu, Zheng;Cui, JianQun(崔建群);...
通讯作者:
Peng, Xi
作者机构:
[Cui, JianQun; Wu, Zheng; Xiao, Debao; Chen, Limiao; Zhang, Yugang; Peng, Xi; Xiao, Shisong] Huazhong Normal Univ, Dept Comp Sci, Wuhan 430079, Peoples R China.
通讯机构:
[Peng, Xi] H
Huazhong Normal Univ, Dept Comp Sci, Wuhan 430079, Peoples R China.
语种:
英文
期刊:
PACIIA: 2008 PACIFIC-ASIA WORKSHOP ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION, VOLS 1-3, PROCEEDINGS
年:
2008
页码:
328-333
会议名称:
Pacific/Asia Workshop on Computational Intelligence and Industrial Application
会议时间:
DEC 19-20, 2008
会议地点:
Wuhan, PEOPLES R CHINA
会议主办单位:
[Peng, Xi;Zhang, Yugang;Xiao, Shisong;Wu, Zheng;Cui, JianQun;Chen, Limiao;Xiao, Debao] Huazhong Normal Univ, Dept Comp Sci, Wuhan 430079, Peoples R China.
会议赞助商:
IEEE, IEEE IES Ind Elect Soc, Wuhan Inst Technol, Huazhong Univ Sci & Technol, Huazhong Normal Univ, Comp & Security Ctr
主编:
Zhang, Y Tan, H Luo, Q
出版地:
10662 LOS VAQUEROS CIRCLE, PO BOX 3014, LOS ALAMITOS, CA 90720-1264 USA
出版者:
IEEE COMPUTER SOC
ISBN:
978-1-4244-4204-1
机构署名:
本校为第一且通讯机构
院系归属:
计算机学院
摘要:
In the past several years, the alert correlation methods have been advocated to discover high-level attack scenarios by correlating the low-level alerts. The causal correlation method based on prerequisites and consequences has great advantages in the process of correlating alerts. But it must depend on complicated background knowledge base and has some limits in discovering new attacks. The cluster can aggregate the relational alerts by computing the similarity between alert attributes, as well as can discover new and simple high-level attacks. However, it is difficult to establish the attrib...

反馈

验证码:
看不清楚,换一个
确定
取消

成果认领

标题:
用户 作者 通讯作者
请选择
请选择
确定
取消

提示

该栏目需要登录且有访问权限才可以访问

如果您有访问权限,请直接 登录访问

如果您没有访问权限,请联系管理员申请开通

管理员联系邮箱:yun@hnwdkj.com