Research on system logs collection and analysis model of the network and information security system by using multi-agent technology

被引:4
作者
Shi Shengyan [1 ]
Shen Xiaoliu [1 ]
Zhao Jianbao [2 ]
Ma Xinke [1 ]
机构
[1] North China Elect Power Univ, Sch Control & Comp Engn, Beijing, Peoples R China
[2] Henan Prov Elect Power Co, Dept Sci & Technol, Zhengzhou, Henan, Peoples R China
来源
2012 FOURTH INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY (MINES 2012) | 2012年
关键词
component; Multi-agent technology; Log collection agent; log collection and analysis system;
D O I
10.1109/MINES.2012.181
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In order to realize the full rang of information security, a variety of network equipment, safe equipment have been applied to deal with all aspects of information security and protection by many enterprise. These devices, systems produce a lot of security event log in the network security protection, and these event log data format are different, and different safety equipment may generate the same alerts logs, not only resulting in generating redundant events, but not conducive to the next work of network security situational awareness. Therefore, this paper proposed a method by using the multi-agent technology to collect and analysis the log data generated by network devices and security devices, and then generating a fixed-format data structure and building the log collection and analysis systems to facilitate the later maintenance and use of data.
引用
收藏
页码:23 / 26
页数:4
相关论文
共 7 条
[1]  
Lixiao, 2005, GUANGDONG RADIO TELE, V14
[2]  
Lvjia, 2006, J CHONGQIONG NORMAL, V23
[3]  
Shaofengjing, 2003, DATA MINING PRINCIPL
[4]  
Shizhongzhi, 2000, INTELLIGENT AGENT IT
[5]  
Tipton H.F., INFORM SECURITY MANA
[6]  
Wujunhua, 2003, J NANJING U TECHNOLO, V25
[7]  
Zhangjianpin, 2004, E ED RES