Exploration of a network security situational awareness model based on multisource data fusion

被引:0
|
作者
Li, Xingguo [1 ,2 ]
Zhong, Yu [2 ]
机构
[1] Sichuan Univ, Coll Comp Sci, Chengdu 610065, Sichuan, Peoples R China
[2] Sichuan Univ, Informat Construction & Management Off, Chengdu 610065, Sichuan, Peoples R China
来源
NEURAL COMPUTING & APPLICATIONS | 2023年 / 35卷 / 36期
关键词
Cyber security situational awareness; Multisource data fusion; Attack trajectory reconstruction; Particle swarm algorithm;
D O I
10.1007/s00521-023-08500-5
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the continuous expansion of the network scale, network technology is also constantly developing. However, with the continuous deterioration of the security environment, the problem of network safety is improving. The traditional single security method has greatly improved the network's stability, but due to the lack of effective cooperation, it becomes increasingly difficult to understand the state changes of the entire network at all times. In such a large environment, research on network security situational awareness can obtain theoretical value and has certain application prospects. The current understanding of cybersecurity situational awareness is not deep enough. Most cases are built in a single-source environment and cannot accurately reflect the perception of attack phases and sequences. To solve this problem, a new model of network safety situation awareness based on multisource data fusion was proposed. The model can effectively perceive the attack stages and sequences and provide an early warning, which is of great importance to improve the network security situation awareness and maintain the network security environment. On the basis of extracting the degree of dissimilarity, in this paper, the fusion-based method is used to generate the attack trajectory, thus forming the multisource data fusion and reconstruction algorithm and finally forming the network security situational awareness model. Compared with the single-source data fusion and reconstruction algorithm, this method has better performance. The final result shows that when the original number of alarms was 1237, after multisource data fusion, the number of alarms was reduced to 124. Moreover, on the basis of multisource data fusion, the detection rate of the number of alarms reached 86.67%, which was 26.67% higher than that of single-source data fusion; the false alarm rate was 5.63%, which was 1.19% lower than that of single-source data fusion. In addition, when using the trajectory reconstruction method to reconstruct the trajectory, the accuracy of the multisource data fusion algorithm was also 1.18% higher than that of the single source, and the completeness also increased by 2.53% compared with the single source. Therefore, the proposed algorithm has higher efficiency, and it is helpful to establish and study the network safety situation consciousness model.
引用
收藏
页码:25083 / 25095
页数:13
相关论文
共 50 条
  • [1] Exploration of a network security situational awareness model based on multisource data fusion
    Xingguo Li
    Yu Zhong
    [J]. Neural Computing and Applications, 2023, 35 : 25083 - 25095
  • [2] A Network Security Situational Awareness Model Based on Information Fusion
    Abasi
    [J]. ADVANCES IN MECHATRONICS, AUTOMATION AND APPLIED INFORMATION TECHNOLOGIES, PTS 1 AND 2, 2014, 846-847 : 1632 - 1635
  • [3] Selection and Fusion of Indicators for Network Security Situational Awareness
    Fu Yanming
    Chen Pan
    Zhong Mi
    Chen Wen
    [J]. MATERIALS SCIENCE AND ENGINEERING, PTS 1-2, 2011, 179-180 : 613 - +
  • [4] Network security situational awareness model based on threat intelligence
    Zhang, Hongbin
    Yin, Yan
    Zhao, Dongmei
    Liu, Bin
    [J]. Tongxin Xuebao/Journal on Communications, 2021, 42 (06): : 182 - 194
  • [5] Network security situational awareness and early warning architecture based on big data
    Zhao, Xuhua
    [J]. INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2024,
  • [6] A New Method of Data Preprocessing for Network Security Situational Awareness
    Lu, Aiping
    Li, Jianping
    Yang, Lin
    [J]. 2010 2ND INTERNATIONAL WORKSHOP ON DATABASE TECHNOLOGY AND APPLICATIONS PROCEEDINGS (DBTA), 2010,
  • [7] A Hierarchical Architectural Model for Network Security Exploring Situational Awareness
    Almeida, Ricardo Borges
    Covalski, Victor
    Machado, Roger
    Leal da Rosa, Diorgenes Yuri
    Yamin, Adenauer Correa
    Donato, Lucas Medeiros
    Pernas, Ana Marilza
    [J]. SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1365 - 1372
  • [8] Survey of Network Security Situational Awareness
    Yao, Jiayu
    Fan, Xiani
    Cao, Ning
    [J]. CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 34 - 44
  • [9] Establishment of nonlinear network security situational awareness model based on random forest under the background of big data
    He, Jinkui
    Su, Weibin
    [J]. NONLINEAR ENGINEERING - MODELING AND APPLICATION, 2023, 12 (01):
  • [10] Situational Awareness Technology in Network Security
    Ye, Zheng-wang
    [J]. 2014 2ND INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE AND HEALTH (ICSSH 2014), PT 4, 2014, 58 : 247 - 251