A Novel Real-Time Aggregation Method on Network Security Events.

Zhitang Li,Yangming Ma,Li Wang,Jie Lei,Jie Ma
DOI: https://doi.org/10.1108/03684921111142467
IF: 2.352
2011-01-01
Kybernetes
Abstract:PurposeThe purpose of this paper is to show how to ensure a real‐time precise aggregation processing of network security events without difficultly determined parameters.Design/methodology/approachThe aggregation method includes the choice of aggregation granularity, consistency of abstraction layer, the expression of all hyper security events (HSEs) of a node in cache, and aggregation algorithm based on classification, etc.FindingsThe aggregation method is capable to provide a real‐time way for good HSEs for next correlation processing with weak and easy parameters to determine.Research limitations/implicationsThe cost of space is not discussed in the method.Practical implicationsThe aggregation method is suitable for real‐time management of difficult issues to resolve massive security events.Originality/valueMany ideas and concepts of the paper are proposed for the first time, such as the expression of all HSEs of a node in cache, weak queue length instead of the weak‐time window and so on.
What problem does this paper attempt to address?