Network Security Situation Awareness Model Based on Multi-Source Fusion

LIU Xiao-wu,WANG Hui-qiang,YU Ji-guo,CAO Bao-xiang
DOI: https://doi.org/10.1166/asl.2012.1852
2012-01-01
Abstract:Firstly,a network security situation awareness model based on multi-source fusion was presented in which the multisource fusion,attack track reconstruction and situation evaluation were considered.Under the instruction of the model,the optimized weights of the D-S evidence fusion were searched using particle swarm optimization in order to reduce the uncertainty in the procedure of fusion.Then,a hierarchy attack track oriented situation awareness method was proposed in combination with the reasoning of the function relation between the threat gene and the threat level.This method was able to accomplish the threat evaluation of the attack step,the attack track and the network.The simulation experiments show that the presented model and methods are effective and accurate and have the aware ness of the dynamic evolvement of the network system,which provides the administrators new method to monitor and administrate their networks.
What problem does this paper attempt to address?