首页> 外文会议>2019 IEEE 28th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises >A Cloud Immune Security Model Based on Alert Correlation and Software Defined Network
【24h】

A Cloud Immune Security Model Based on Alert Correlation and Software Defined Network

机译:基于警报关联和软件定义网络的云免疫安全模型

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we explore the AIS approach to develop an agent-based detection method to analyze network traffic. The system works in conjunction with attack graph based correlation and software-defined network (SDN) technology to mitigate attacks. In the correlation technique, alerts are correlated through an attack graph which improves detection performance by decreasing the false alert rate. The false alert reduction can avoid the negative effect that an SDN countermeasure can bring to the cloud Service Level Agreement (SLA) on the absence of threats. This work was tested for multi-step and distributed denial of service (DDoS) attacks. Results have shown the addition of the correlation technique can aid to the detection performance of AIS detection systems.
机译:在本文中,我们探索了AIS方法,以开发一种基于代理的检测方法来分析网络流量。该系统与基于攻击图的相关性和软件定义网络(SDN)技术结合使用,可缓解攻击。在关联技术中,警报通过攻击图进行关联,该攻击图通过降低错误警报率来提高检测性能。错误警报的减少可以避免SDN对策在没有威胁的情况下可能给云服务级别协议(SLA)带来的负面影响。这项工作已经过多步骤和分布式拒绝服务(DDoS)攻击的测试。结果表明,相关技术的添加可以帮助提高AIS检测系统的检测性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号