A New Security Event Correlation Analysis Engine Based on Rule-Tree-Matching


연구 분야: Safety



학회: 2022 IEEE 5th Advanced Information Management, Communicates, Electronic and Automation Control Conference (IMCEC)


초록

The magnitude of security data keeps increasing with the frequent occurrence of security events. And massive security data is causing increasing bottlenecks of correlation analysis engine in terms of matching efficiency, operating performance and rule expression, etc. In order to solve the above problems, this paper proposes a security event correlation analysis engine based on the Rule-Tree-Matching. The design and implementation of the security event correlation analysis engine have been completed. Also, several comparative experiments have been done to prove the advancement and feasibility of the Rule-Tree-Matching engine.


Author Profile
Peng Lu

China Academy of Engineering Physics Institute of Computer Application Mianyang China

China
Author Profile
Ruobin Zhang

China Academy of Engineering Physics Institute of Computer Application Mianyang China

China
Author Profile
Guo Wu

China Academy of Engineering Physics Institute of Computer Application Mianyang China

China

📄 논문 정보

발행 연도 2022년
인용수 119
출판 국가 China
사이트 IEEE
좋아요 수 0

연관 논문 목록 (333건)