西北工业大学计算机学院,西安,710072
网络首发:2008-12-10,
纸质出版:2008
移动端阅览
安喜锋, 李伟华, 刘尊. 网络安全协同防卫系统研究与实现[J]. 西安交通大学学报, 2008,42(12):1495-1499.
安喜锋, 李伟华, 刘尊. Research and Implementation of Network Security Cooperative Defense System[J]. 2008, 42(12): 1495-1499.
为了解决防卫体系中各安全模块缺乏协同控制以及不能有效发挥整体效应的问题
提出了一种基于代理的协同控制框架.将各个安全模块关联起来
以实现相互通信和协同工作.在此基础上
构建了包括预警定位、协同安全审计及态势评估、协同事故恢复、网络伪装等功能的网络安全协同防卫系统(NSCDS).以基于机器学习的系统调用序列审计模型为例
对关键技术模块进行了分析和验证
结果表明NSCDS软件在百兆级带宽下
安全审计预警漏报率小于 6%
误报率小于 8%
各功能模块工作稳定且配合正常
充分显示出系统的综合优势
实现了网络安全多层次、全方位的协同防卫目标.
A novel network security cooperative defense technology is studied and a cooperative control framework based on agent mechanism is proposed to solve the lack of cooperative control and whole effect in traditional defense systems. The technology supports both IPv4 and IPv6 protocols and security modules in the framework are associated with each other to accomplish communication and work together. Furthermore
a network security cooperative defense system is composed and the key functions that support the early-alert
audit
accident recovery
network camouflage and so on are also achieved. The pivotal research is emphasized on the key technologies of system call sequences audit model based on machine learning and cooperative accident recovery. Under the condition of 100 M Data flow speed
the NSCDS software's false negative is less than 6% and its false positive is less than 8%. Besides
all module functions work normally and the system can be used to carry out cooperative defense capability.
CNCERT/CC. 2006 annual report by CNCERT [EB/OL]. [2007-10-10]. http:∥www.cert.org.cn, 2007.
BERK V H, GRAY R S, BAKOS G. Using sensor networks and data fusion for early detection of active worms [C]∥Proceedings of the SPIE AeroSense: Sensors, and Command, Control, Communications, and Intelligence Technologies for Homeland Defense and Law Enforcement II. Orlando,FL, USA: SPIE, 2003: 92-104.
傅翀,王娟,秦志光,等. 宏观网络安全预警与应急响应系统 [J]. 电子科技大学学报, 2006, 35(4): 702-705.
FU Chong, WANG Juan, QIN Zhiguang,et al. Macro network security warning and emergency response system [J]. Journal of University of Electronic Science and Technology of China, 2006, 35(4): 702-705.
胡华平,张怡,陈海涛. 面向大规模网络的入侵检测与预警系统研究 [J]. 国防科技大学学报, 2003,25(1):21-25.
HU Huaping, ZHANG Yi, CHEN Haitao. The study of large scale networks intrusion detection and warning system [J]. Journal of National University of Defense Technology, 2003,25(1):21-25.
BALEPIN I, MALTSEV S, ROWE J, et al. Using specification-based intrusion detection for automated response[C]∥Proceeding of the 6th International Symposium on Recent Advances in Intrusion Detection. Berlin, Germany: Springer, 2003: 136-154.
Nsfocus. Sendmail异步信号处理竞争条件漏洞[EB/OL]. [2007-10-10]. http:∥www.nsfocus.net/vulndb/8596.
王新昌,杨艳,刘育楠. 一种基于局域网络监控日志的安全审计系统 [J].计算机应用, 2007, 27(2): 292-294.
WANG Xinchang, YANG Yan, LIU Yunan. Security audit system based on LAN monitoring logs [J]. Journal of Computer Applications, 2007, 27(2): 292-294.
卿斯汉,刘文清,温红子. 操作系统安全 [M]. 北京:清华大学出版社,2004: 25-26.
雷浩,黄建,冯登国. 协同环境中共有资源的细粒度协作访问控制策略 [J]. 软件学报, 2005, 16(5): 1000-1011.
LEI Hao, HUANG Jian, FENG Dengguo. A fine-grained coalition access control policy for jointly-owned resources in collaborative environments [J]. Journal of Software, 2005, 16(5): 1000-1011.
HIRAISHI H, MIZOGUCHI F. Design of a visual browser for network intrusion detection[C]∥10th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises. Piscataway, NJ, USA: IEEE, 2001: 132-137.
0
浏览量
4
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621