首页|期刊导航|网络安全与数据治理|高噪声日志攻击源识别方法研究及实现

高噪声日志攻击源识别方法研究及实现OA

Research on methods and systems for identifying high-noise log attack sources

中文摘要英文摘要

随着信息系统规模的扩大与网络攻击手段的多样化,网络安全态势感知平台及其他运营保障平台在面对海量异构日志时,普遍存在告警疲劳、误报率高、攻击溯源困难等问题.针对高噪声日志环境下的攻击源识别与威胁溯源难题,提出一种高噪声日志攻击源识别方法,该方法使用了基于多维规则的攻击源IP动态评分模型,实现攻击源威胁等级的动态评估与更新.同时,系统利用知识图谱完成攻击链重构与可视化分析,提升安全事件的可解释性与处置效率.实验结果表明,该方法在水利行业真实日志数据上实现了99.6%的日志浓缩率,误报率降低至8.3%,显著提升安全运营效率与响应能力.研究成果为行业级网络安全智能化运营提供了可行技术路径.

With the expansion of information system scale and the diversification of network attack methods,network security situation aware-ness platforms and other operation and support platforms generally suffer from problems such as alarm fatigue,high false alarm rates,and diffi-culty in attack attribution when facing massive heterogeneous logs.To address the challenges of attack source identification and threat attribu-tion in high-noise log environments,this paper proposes a method for identifying attack sources in high-noise logs.This method uses a dynamic scoring model of attack source IPs based on multi-dimensional rules to achieve dynamic assessment and updating of the threat level of attack sources.Simultaneously,the system utilizes knowledge graphs to complete attack chain reconstruction and visualization analysis,improving the interpretability and handling efficiency of security incidents.Experimental results show that this method achieves a log compression rate of 99.6%on real log data in the water conservancy industry,reducing the false alarm rate to 8.3%,significantly improving security operation effi-ciency and response capabilities.The research results provide a feasible technical path for intelligent operation of industry-level network security.

高原;汪辰瑞

安徽省水科学与智慧水利重点实验室,安徽 合肥 230091||安徽省大禹水利工程科技有限公司,安徽 合肥 230088安徽省水科学与智慧水利重点实验室,安徽 合肥 230091||安徽省建筑工程质量监督检测站有限公司,安徽 合肥 230088

信息技术与安全科学

网络安全日志降噪动态评分模型知识图谱威胁溯源

cybersecuritylog denoisingdynamic scoring modelknowledge graphthreat attribution

《网络安全与数据治理》 2026 (1)

14-19,6

10.19358/j.issn.2097-1788.2026.01.003

评论