The invention relates to a
network security incident association analysis
system comprising a
network security incident collection layer, a communication
network layer, an association analysis layer and a management
presentation layer. A set of
Web structure-based on-line association analyzing and
monitoring system capable of distributed
network security incident collection, multi-point implementation association analysis, center comprehensive judgment and real-time communication is built by carrying out digital management of whole processes of unified collection, transmission, analysis, distribution and the like to complex IT (
Information Technology) resources in a
computer network and various security logs and incidents which are continuously generated in the operational process of the security defense facilities of the
computer network, utilizing an incident associativity prediction principle and combining incident flow space-time window filter, log string leading match quick dynamic analysis and a polydimensional
mass incident strong
algorithm to carry out association analysis on situations before, during and after network security incidents to the network security incidents. The network security incident association analysis
system is used for effectively managing the security of complex IT resources in the
computer network for a long term, can truly and accurately reflect the network
information security of the computer network and the security situation of the business
system data, and provides a quantitative standard for checking the
information security level of the computer network.