A Network Security Situation Awareness Model Based on Stream Cube

Yan Jia
2011-01-01
Abstract:Network security situation awareness is a new trend of network security monitoring technology.The awareness of the situation is very important to network security.Based on the existing research about data cube,we propose a network security situation awareness model to describe and abstract the multi-dimensional analysis structure related to the network security situation awareness.We can analyze the network security situation from the aspect of the network security events' statistical characteristics based on this model and give an instance of the model based on frequency,trend and entropy characteristics.Then we improve the efficiency of the method by studying the correlation of the cells among the neighboring levels in the data cube on the basis of keeping the accuracy of the results.We also prove that we only need to get the lowest level cube's characteristics from the raw data,and get the higher level cube's characteristics by an indirect way.Building the practical applications and extensive experiments based on the real network security dataset demonstrates the effectiveness of the proposed model and methods.
What problem does this paper attempt to address?