摘要
安全审计系统作为一种对用户网络行为的有效监督手段,对网络行为的可追溯和可控制起着重要作用。文中提出了一种基于动态网络可信度量的安全审计方法。该方法根据网络的实时日志信息,周期性对其进行数据挖掘生成规则,并将规则应用到数据流的过滤中。根据数据流与规则的匹配情况进行动态的可信度量,使得系统对可信行为和危险行为形成不同的安全访问控制机制。较以前以固定规则应对变化的访问控制和过滤,所提出的方法具有很好的适用性和灵活性。
Security audit system plays an important role in user network behavior. It makes sure that the network behavior can be controlled and traced back. It proposed a design of security audit based on dynamic amount of network behavior trust, which periodically gen- erated rules by mining latest logs and applied rules to the date stream filtering. This design generated different security access control mechanism for trusted behavior and risk behavior,based on matching date flow with roles to measure network behavior trust. Comparing to existing systems which made constant rules to respond to mutative access control and filtering, this design had great applicability and flexibility.
出处
《计算机技术与发展》
2012年第5期250-253,共4页
Computer Technology and Development
基金
国家电网公司科技攻关团队项目(SG11034)
关键词
数据挖掘
行为可信
安全审计
访问控制
data mining
behavior trust
security audit
access control