跳到主要导航 跳到搜索 跳到主要内容

Network Security Situation Awareness Based on Spatio-temporal Correlation of Alarms

  • Zehua Ren
  • , Yang Liu
  • , Huixiang Liu
  • , Baoxiang Jiang
  • , Xiangzhen Yao
  • , Lin Li
  • , Haiwen Yang
  • , Ting Liu

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

Traditional intrusion detection systems often deal with massive alarms based on specific filtering rules, which is complex and inexplicable. In this demo, we developed a network security situation awareness (NSSA) system based on the spatiotemporal correlation of alarms. It can monitor the security situation from the temporal dimension and discover abnormal events based on the time series of alarms. Also, it can analyze alarms from the spatial dimension on the heterogeneous alarm graph and handle alarms in batches of events. With this system, system operators can filter most irrelevant alarms quickly and efficiently. The rich visualization of alarm data could also help find hidden high-risk attack behaviors.

源语言英语
主期刊名INFOCOM WKSHPS 2022 - IEEE Conference on Computer Communications Workshops
出版商Institute of Electrical and Electronics Engineers Inc.
ISBN(电子版)9781665409261
DOI
出版状态已出版 - 2022
活动2022 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2022 - Virtual, Online, 美国
期限: 2 5月 20225 5月 2022

出版系列

姓名INFOCOM WKSHPS 2022 - IEEE Conference on Computer Communications Workshops

会议

会议2022 IEEE Conference on Computer Communications Workshops, INFOCOM WKSHPS 2022
国家/地区美国
Virtual, Online
时期2/05/225/05/22

学术指纹

探究 'Network Security Situation Awareness Based on Spatio-temporal Correlation of Alarms' 的科研主题。它们共同构成独一无二的指纹。

引用此