An Intelligent Agent-Oriented System for Integrating Network Security Devices and Handling Large Amount of Security Events

To integrate network security devices to make them act as a battle team and efficiently handle the large amount of security events produced by various network applications, Network Security Intelligent Centralized Management is a basic solution. In this paper, we introduce an intelligent agent-oriented Network Security Intelligent Centralized Management System, and give a description about the system model, mechanism, hierarchy of security events, data flow diagram, filtering and transaction and normalization of security events, clustering and merging algorithm, and correlation algorithm. The experiment shows that the system can significantly reduce false positives and improve the quality of security events. It brings convenience for security administrators to integrate security devices and deal with large security events.

[1]  Dario Forte Log correlation: Part 2 , 2004 .

[2]  Anton Chuvakin Security Event Analysis through Correlation , 2004, Inf. Secur. J. A Glob. Perspect..

[3]  Hervé Debar,et al.  Aggregation and Correlation of Intrusion-Detection Alerts , 2001, Recent Advances in Intrusion Detection.

[4]  Dario Forte The “Art” of log correlation , 2004 .