会议专题

MS2IFS : A Multiple Source-based Security Information Fusion System

Security Information Fusion System has recently become one of the major topics in the research area of information security. A great deal of security devices and components have been deployed in network information systems. While improving the systems security performance, they produced lots of redundant or unreliable information.Through the technologies of alert fusion and correlation analysis, alert redundancy can be decreased, administration pressure can be reduced and alert accuracy can be raised effectively. We propose the system architecture of multisource security information fusion (MS2IFS), and discuss the design ideas and algorithm implementation of MS2IFS key modules. The results of testing on offline alert logs and online simulated attack data proved the feasibility and validity of MS2IFS system and satisfied the design requirement,presenting preferable.

information fusion intrusion detection alert correlation risk evaluation

Jun Chang Jiang Yu Yijian Pei

School of Information Science and Engineering Yunnan University,Kunming,PR China

国际会议

2010 International Conference on Communications and Intelligence Information Security(2010年国际信息与智能安全学术会议 ICCIIS2010)

南宁

英文

215-219

2010-10-13(万方平台首次上网日期,不代表论文的发表时间)