Network Security Situation Awareness Technology Based on Multi-source Heterogeneous Data

Daojuan Zhang,Kexiang Qian,Wenhui Wang,Fuyang fang,Chonghua Wang,Xi Luo
DOI: https://doi.org/10.1145/3444370.3444607
2020-12-04
Abstract:With the development of information technology, the scale of the network continues to expand, and the security issues continue to increase. The complexity of the network security situation is increasing and the importance of the network security situational awareness continues to increase. The data sources are wide, the type and the number are large in a large-scale network environment currently. This paper comprehensively studies the network security situational awareness technology based on multi-source heterogeneous data. In addition, this paper introduces the origin, concept and the model of the network situational awareness, as well as the characteristics of network security situational awareness based on multi-source heterogeneous data fusion. Finally, the key technologies in the security situational awareness such as the extraction of situational elements, multi-source data fusion, situation assessment, situation prediction and visual display are introduced.
What problem does this paper attempt to address?
The paper attempts to address the issue of how to achieve network security situational awareness technology based on multi-source heterogeneous data in a large-scale network environment. With the development of information technology, network security issues have become increasingly complex, and traditional single data source analysis methods can no longer meet current needs. Therefore, this paper aims to study and explore how to use multi-source heterogeneous data fusion technology to improve the comprehensiveness and accuracy of network security situational awareness, thereby better coping with complex network security threats. Specifically, the paper mainly focuses on the following aspects: 1. **The origin, concept, and model of network security situational awareness**: Introduce the basic concepts of network security situational awareness and its development background. 2. **Characteristics of multi-source heterogeneous data fusion**: Discuss the characteristics of multi-source heterogeneous data in a large-scale network environment and its application in network security situational awareness. 3. **Key technologies**: Provide a detailed introduction to the key technologies in network security situational awareness, including situational element extraction, multi-source data fusion, situational assessment, situational prediction, and visual display. Through this research, the paper hopes to provide effective tools and methods for network security managers so that they can better understand and control the network environment, and timely detect and respond to potential security threats.