Cyber Security Situation Awareness Based on Data Mining
Situation awareness is a kind of the third generation of information security technology,which aims to provide the global seeurity views of the (e)yberspace for administrators.A framework of eyber security situation awareness based on data mining is proposed in this paper.The framework can be viewed from two perspectives,one is data flow,which presents the abstracting of cyber data,and the other one is logic view,which presents the procedure of situation awareness.The frameworks core component is correlation state machine,which is an extension of state machine.The correlation state machine is a data structure of achieving situation awareness,which is created based on the technology of data mining.After being created,it can be reed to assess and predict the threat situation to achieve eyber knowledge.We conclude with an example of how the framework can be applied to real world to provide cyber security situation for administrators.
cyber security situation awareness correlation state machine threat prediction threat assessment
Liu Jie Feng Xuewei Li Jin Wang Dongxia
Beijing Institute of System Engineer, Beijing 100101, China Beijing Institute of System Engineer, Beijing 100101, China ; Nation Key Laboratory of Science and T
国际会议
太原
英文
254-258
2012-12-08(万方平台首次上网日期,不代表论文的发表时间)