An intelligent agent-oriented system for integrating network security devices and handling large amount of security events

  • Authors:
  • Yang-Ming Ma;Zhi-Tang Li;Jie Lei;Li Wang;Dong Li

  • Affiliations:
  • Sch. of Computer Sci. & tech., Huazhong University of Sci. & Tech., Wuhan, China;Sch. of Computer Sci. & tech., Huazhong University of Sci. & Tech., Wuhan, China;Sch. of Computer Sci. & tech., Huazhong University of Sci. & Tech., Wuhan, China;Sch. of Computer Sci. & tech., Huazhong University of Sci. & Tech., Wuhan, China;Sch. of Computer Sci. & tech., Huazhong University of Sci. & Tech., Wuhan, China

  • Venue:
  • PAISI'07 Proceedings of the 2007 Pacific Asia conference on Intelligence and security informatics
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

To integrate network security devices to make them act as a battle team and efficiently handle the large amount of security events produced by various network applications, Network Security Intelligent Centralized Management is a basic solution. In this paper, we introduce an intelligent agent-oriented Network Security Intelligent Centralized Management System, and give a description about the system model, mechanism, hierarchy of security events, data flow diagram, filtering and transaction and normalization of security events, clustering and merging algorithm, and correlation algorithm. The experiment shows that the system can significantly reduce false positives and improve the quality of security events. It brings convenience for security administrators to integrate security devices and deal with large security events.