{"title":"基于NetFlow的网络态势感知信息获取方法","authors":"Huiqiang Wang, Renjie Zhou, Yingjie He","doi":"10.1109/ASEA.2008.20","DOIUrl":null,"url":null,"abstract":"Network situation information acquisition plays an important role in the entire process of network situation awareness. In this paper, we presented a multi-level, multi-perspective and multi-granularity traffic information acquisition method to get traffic information. In addition, we presented a multi-layer detection model that combines baseline based detection layer and signature based detection layer to acquire security incident information. Accordingly, we profiled portpsilas normal behavior for baseline based detection by statistical method and established an incident signature base for signature based detection.","PeriodicalId":223823,"journal":{"name":"2008 Advanced Software Engineering and Its Applications","volume":"49 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"An Information Acquisition Method Based on NetFlow for Network Situation Awareness\",\"authors\":\"Huiqiang Wang, Renjie Zhou, Yingjie He\",\"doi\":\"10.1109/ASEA.2008.20\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Network situation information acquisition plays an important role in the entire process of network situation awareness. In this paper, we presented a multi-level, multi-perspective and multi-granularity traffic information acquisition method to get traffic information. In addition, we presented a multi-layer detection model that combines baseline based detection layer and signature based detection layer to acquire security incident information. Accordingly, we profiled portpsilas normal behavior for baseline based detection by statistical method and established an incident signature base for signature based detection.\",\"PeriodicalId\":223823,\"journal\":{\"name\":\"2008 Advanced Software Engineering and Its Applications\",\"volume\":\"49 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-12-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2008 Advanced Software Engineering and Its Applications\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ASEA.2008.20\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 Advanced Software Engineering and Its Applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ASEA.2008.20","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
An Information Acquisition Method Based on NetFlow for Network Situation Awareness
Network situation information acquisition plays an important role in the entire process of network situation awareness. In this paper, we presented a multi-level, multi-perspective and multi-granularity traffic information acquisition method to get traffic information. In addition, we presented a multi-layer detection model that combines baseline based detection layer and signature based detection layer to acquire security incident information. Accordingly, we profiled portpsilas normal behavior for baseline based detection by statistical method and established an incident signature base for signature based detection.