透過您的圖書館登入
IP:3.144.253.161
  • 學位論文

應用於網路安全情境察覺系統之警訊衝突解析模型

Alert Conflict Resolution Model in Network Security Situation Awareness System

指導教授 : 陳奕明
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


情境察覺(Situation Awareness, SA)簡單來說就是知道現在發生什麼事並能知道如何回應,而其觀念由最初之飛航安全領域被引申於其他動態的、複雜的及需要人力介入之情境中,近年來也在資訊安全研究的領域中興起,即網路安全情境察覺(Network Security Situation Awareness)。然而,在情境察覺概念中使用多種警訊系統來確保對外在環境的瞭解並予以回應,其中所牽涉的問題可能包括發生資訊超載(Alert Overload)以擾亂管理人員,或儘管各系統回報之狀況並沒有錯誤,但資訊依然可能發生衝突(Alert Conflict)使管理人員不知所措等,所衍生之問題同樣的也將在網路安全防護資安監控中心(Security Operation Center, SOC)中發生。因此我們提出了異質網路感應器管理服務(HNSMS),目的則是為了解析警訊的衝突。首先利用各異質網路感應器所回報警訊之可信度及其權重之衡量進行警訊融合(Alert Fusion),此外也考慮經由單一時間點之警訊融合後尚可能造成的偵測漏報問題,進一步配合安全政策,利用其它輔佐資訊再次進行警訊融合,最後以模擬案例的方式進行系統的推演,期望藉由最終警訊以了解系統/網路整體之安全狀態,舒緩警訊衝突所帶來之風險。

並列摘要


SA is simply “knowing what is going on so you can figure out what to do”. The term was first used by U.S. Air Force (USAF) fighter aircrew and was considered to be essential for those who are responsible for being in control of complex, dynamic systems and high-risk situations. In recent years, Network Security Situation Awareness is a hot research in the domain of information security. However, these different types of sensor for better situation awareness could result in two problems. First is the “Alert Overload”, and it could disturb the security administrators. Second is the “Alert Conflict”. Though each of these sensors did not report the wrong message, it could be happened. Therefore, these problems could occur in SOC as well. This thesis addresses these problems in SOC using a Heterogeneous Network Sensors Management Service (HNSMS) in order to solve the alert conflict. We use Alert Confidence Fusion method at first to fuse the alerts from different sensors and consider the confidence and weight of alerts in the fusion technique. Moreover, we also consider that some attack cannot be detected in a single time, so we use Fuzzy Cognitive Maps (FCM) and policy to fuse the multiple inputs. Finally, the final alerts help to improve the understanding of whole system security and allow security administrators to take appropriate responses. To summarize, HNSMS refine the alert from different sensors by means of two data fusion techniques and relieve the risk from alert conflict.

參考文獻


[17] Ambareen Siraj, Rayford B. Vaughm, and Susan M. Bridges, “Intrusion Sensor Data Fusion in an Intelligent Intrusion Detection System Architecture," In Proceedings of the 37th Hawaii International Conference on System Sciences, IEEE, 5-8 Jan, 2004.
[18] Ambareen Siraj, Susan M. Bridges, and Rayford B. Vaughn, “Fuzzy Cognitive Maps for Decision Support in an Intelligent Intrusion Detection System,” In IFSA World Congress and 20th NAFIPS International Conference, 25-28 July, 2001.
[19] Amy R. Pritchett and R. John Hansman, “Pilot Non-Conformance to Alerting System Commands During Closely Spaced Parallel Approaches,” MIT Aeronautical Systems Lab. Rep., ASL-97-2, Cambridge, MA, Jan. 1997.
[23] David L. Hall, “Mathematical Techniques in Multisensor Data Fusion,” 1992, Atrech House, Boston, MA.
[24] Dong Yu and Deborah Frincke, “Alert Confidence Fusion in Intrusion Detection Systems with Extended Dempster-Shafer Theory,” 43rd ACM Southeast Conference, March 18-20, 2005, Kennesaw, GA, USA.

被引用紀錄


陳婉宜(2008)。基於D-S證據理論之階層式網路安全情境察覺系統〔碩士論文,國立中央大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0031-0207200917355288

延伸閱讀