A confidence-based network security alarm processing method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- UNIV OF ELECTRONICS SCI & TECH OF CHINA
- Publication Date
- 2021-05-14
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention proposes a method for processing network security alarms based on confidence, which is used to eliminate useless and redundant network security equipment alarms and improve the analysis efficiency of network security intrusion events. In the field of network security. Background technique
[0002] With the rapid development of computer information and communication technology, network security attacks occur from time to time. At this stage, enterprises and institutions basically rely on security devices and the logs generated by security devices for defense and re-analysis of security attack events. False positives and negative negatives are common in current network security devices, and there are a large number of bots on the Internet. These bots are often used by criminals as scanners to scan the entire network. Therefore, the network security device also generates a large number of useless alarms. Contents of the invention [000...