信息网络安全 ›› 2016, Vol. 16 ›› Issue (11): 40-44.doi: 10.3969/j.issn.1671-1122.2016.11.007

• • 上一篇    下一篇

网络安全数据可视分析系统的设计与实现

刘汝隽(), 辛阳   

  1. 北京邮电大学网络空间安全学院,北京 100876
  • 收稿日期:2016-08-20 出版日期:2016-11-20 发布日期:2020-05-13
  • 作者简介:

    作者简介:刘汝隽(1991—),女,河北,硕士研究生,主要研究方向为信息安全、计算机网络安全;辛阳(1977—),男,山东,副教授,博士,主要研究方向为移动通信安全、计算机网络安全。

  • 基金资助:
    国家高技术研究发展计划(国家863 计划)[2015AA017201]

Design and Implementation of Network Security Data Visualization and Analysis System

Rujun LIU(), Yang XIN   

  1. School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Received:2016-08-20 Online:2016-11-20 Published:2020-05-13

摘要:

文章针对网络异常数据展示形式单一、时间延迟的问题,提出一个采用丰富可视化形式和实时展示网络安全态势的网络安全数据可视分析系统。该系统功能主要包括:网络异常数据监测、态势感知和预测、安全预警与风险监控。首先,通过数据采集模块收集设备原始数据;其次,利用数据预处理模块将原始数据转化成标准形式;再次,使用数据分析模块将标准数据进行分析和检测,识别异常数据并形成网络态势;最后,采用网络地图、拓扑图、时序图等多种可视化形式对分析结果进行实时展示。该系统将数据产生、处理、分析和展示过程相结合,实现态势状态实时预测,提高网络设备监控效率。

关键词: 网络安全, 可视化, 态势感知, 异常检测

Abstract:

Focus on the issues that network abnormal data is displayed in an single way and it can’t be shown in real time, a network security data visualization and analysis system is designed and implemented. The functions of the system are network abnormal data monitoring, situation awareness and risk monitoring. Firstly, data collection model gathers original data of devices. Secondly, data preprocessing model transforms original data into standard format. Thirdly, data analysis model distinguishes abnormal data and forms network situation by analysing and detecting standard data. Finally, analysis results are real-time displayed by network map, topological graph, sequence chart,etc. The system combines data collection, data preprocessing, data analysis and data display, meanwhile implements real-time situation forecast and improves the effeciency of network device monitoring.

Key words: network security, visualization, situation awareness, anormaly detection

中图分类号: