Cyber Security Situation Awareness Based on Data Mining

Author:

Liu Jie1,Feng Xue Wei2,Li Jin2,Wang Dong Xia2

Affiliation:

1. Beijing Institute of System Engineering

2. Nation Key Laboratory of Science and Technology on Information System Security

Abstract

Situation awareness is a kind of the third generation of information security technology, which aims to provide the global security views of the cyberspace for administrators. A framework of cyber security situation awareness based on data mining is proposed in this paper. The framework can be viewed from two perspectives, one is data flow, which presents the abstracting of cyber data, and the other one is logic view, which presents the procedure of situation awareness. The frameworks core component is correlation state machine, which is an extension of state machine. The correlation state machine is a data structure of achieving situation awareness, which is created based on the technology of data mining. After being created, it can be used to assess and predict the threat situation to achieve cyber knowledge. We conclude with an example of how the framework can be applied to real world to provide cyber security situation for administrators.

Publisher

Trans Tech Publications, Ltd.

Subject

General Engineering

Reference13 articles.

1. Bass T. Multi-Sensor Data Fusion for next Generation Distributed Intrusion Detection Systems [C]. 1999 IRIS National Symposium on Sensor and Data Fusion, Laurel, USA, 1999(1): 24-27.

2. Bass T. Intrusion Detection Systems and Multi-Sensor Data Fusion: Creating Cyberspace Situation Awareness [J]. Communications of the ACM, 2000, 43(4): 99-105.

3. Feng Xuewei, Wang Dongxia. A Framework of Network Security Situation Analysis Based on the Technologies of Event Correlation and Situation Assessment. 2011 International workshop on Frontiers of Secure Networks.

4. Wang Huiqiang, Lai Jibao, Hu Mingming. Research on the key implement technology of network security situation awareness[J]. Geomatics and Information Science of Wuhan University. 2008, Vol. 33 No. 10 (in Chinese).

5. Wang Yanbo, Wang Huiqiang, Wang Xiufeng, Yu Ming. Design of multi-source and heterogeneous log sensor for network situational awareness. Transducer and Microsystem Technologies. 2010. Vol. 29 No. 3 (in Chinese).

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3