欢迎访问中国科学院大学学报,今天是

中国科学院大学学报 ›› 2001, Vol. 18 ›› Issue (2): 167-171.DOI: 10.7523/j.issn.2095-6134.2001.2.014

• 研究简报 • 上一篇    下一篇

托管式安全监控系统

连一峰, 戴英侠, 王航   

  1. 中国科学院研究生院信息安全国家重点实验室, 北京 100039
  • 收稿日期:2001-04-29 发布日期:2001-03-10
  • 作者简介:连一峰,男,1974年6月生,博士生
  • 基金资助:

    国家信息化工作领导小组计算机网络系统安全技术研究项目资助课题;国家重点基础研究发展规划项目资助课题(G1999035801)

Managed Security Monitoring System

Lian Yifeng, Dai Yingxia, Wang Hang   

  1. State Key Laboratorg of Information Semrity, The Graduate School of the Chinese Academy of Sciences, Beijing 100039
  • Received:2001-04-29 Published:2001-03-10

摘要:

分析了目前托管式安全监控 (MSM)系统存在的优势及缺陷,提出了将机器学习应用到MSM系统的观点,以提高系统的分析效率,克服存在的社会工程安全问题.MSM系统是为了克服单一安全技术的缺陷而兴起的大范围、综合化、与人工分析相结合的安全服务系统.通过对客户网络中安全事件的实时监控,依靠系统安全分析员及安全知识库,提供对网络入侵的准确判断和即时响应

关键词: 托管式安全监控, 入侵检测, 机器学习, 数据挖掘

Abstract:

Managed Security Monitoring System is a kind of global,synthetic security service system cooperating with artificial analysis which is put forward to overcome defects of single security technology.It can supply appropriate judgment and instant response to network intrusions.Advantages and disadvantages of MSM systems are analyzed.The viewpoint of applying Machine Learning to MSM systems is presented in order to improve analysis efficiency and overcome security flaws relating to social engineering.

Key words: managed security monitoring, intrusion detection, machine learning, data mining

中图分类号: