earticle

논문검색

Applying Basic-Elements and the Extension Theory to Alert-centric Event Correlation for Unified Network Security Management

초록

영어

With increasing requirements of network users for intelligent security management, unified network security management has become a fashion, and a remarkable development trend is the adoption of an alert-centric event correlation manner. This paper then introduces Extenics into the study on alert-centric event correlation for unified network security management and proposes a formalized approach using basic-elements based on the extension theory. The proposed approach utilizes the basic-elements to formalize the representations of alerts, events, and also correlation policies for network security in a unified manner, and then makes full use of the extension theory to formalize basic operators for extension expressions and extension functions in order to realize alert-centric event correlation. Validation scenarios of timing constraints show that, the proposed approach provides a prospective way to alert-centric event correlation for unified network security management by introducing basic-elements and utilizing extension expressions and extension functions with the use of containing analysis, sequencing analysis and extension transformations based on the extension theory.

목차

Abstract
 1. Introduction
 2. Formal Representations of Security Information and Knowledge usingBasic-elements
  2.1. Application of basic-elements
  2.2. Formal representations of security information for alerts and events
  2.3. Formal representations of security knowledge for correlation policies
 3. Application of the Extension Theory for Alert-centric Event Correlation
  3.1. Basic operators for extension expressions
  3.2. Formalization of extension functions
 4. Validation Scenarios
  4.1. Extension functions for validation
  4.2. Scenario analysis
 5. Conclusions
 Acknowledgements
 References

저자정보

  • Hui Xu School of Computer Science, Hubei University of Technology, Wuhan, China
  • Chunzhi Wang School of Computer Science, Hubei University of Technology, Wuhan, China
  • Hongwei Chen School of Computer Science, Hubei University of Technology, Wuhan, China
  • Zhiwei Ye School of Computer Science, Hubei University of Technology, Wuhan, China

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.