Alarm correlation analysis-based unknown attack scene detection method
A technology of correlation analysis and scene detection, which is applied in the field of unknown attack scene detection based on correlation analysis, can solve the problems of large number of alarm information and fragmented content, and achieve the effect of improving the effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0064] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present invention, and do not limit the protection scope of the present invention.
[0065] Such as figure 1 As shown, the present invention provides a method for detecting unknown attack scenarios based on alarm correlation analysis, comprising the following steps:
[0066] S1. Preprocess a large number of intrusion alarms from multiple sources to generate an alarm set.
[0067] S11. Identify the alarm data format of the intrusion detection system of each manufacturer.
[0068] S12. Formatting the IDS alarm data, using regular expressions to extract the eight fields of alarm name, alarm number, alarm level, source IP, destination IP, source port, dest...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


