基于回声状态网络识别的网络安全设备联动系统设计
DOI:
CSTR:
作者:
作者单位:

国能朔黄铁路发展有限责任公司信息中心

作者简介:

通讯作者:

中图分类号:

基金项目:


Design of Network Security Equipment Linkage System Based on Echo State Network Recognition
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    网络环境是复杂性和变化性,使得系统难以及时发现网络中的异常行为或攻击,且联动系统不同设备间无法有效实现数据共享,从而使网络安全设备联动系统无法有效应对新型恶意攻击,导致阻断响应时间长、丢包率高的问题。因此,为提高网络的安全性,设计了基于回声状态网络识别的网络安全设备联动系统。在网络安全设备联动系统硬件设计中,采用开放接口方式,将各自独立的防火墙、入侵检测系统等各设备通过接口连接,实现信息的共享,确保有效实现联动,并使用NetFlow Collector、Apache Spark和Snort处理模块进行信息采集、处理和检测。然后通过Cobalt Strike设备联动决策装置,触发联动控制机制,并通过利用WatchGuard联动控制平台,实现网络设备联动防御。在软件设计中,为提高异常检测的准确性,在Snort处理模块中引入回声状态网络展开各设备数据异常检测。最后,基于检测结果,在Cobalt Strike设备中采用改进FUP算法进行网络安全事件关联挖掘,以发现潜在攻击信息,并提交给决策层的策略判决点进行策略触发,通过检索相应处理策略完成策略触发,最终策略判决点将安全事件处理策略命令下达给WatchGuard联动控制平台,从而完成联动操作。由测试结果可知,该系统总体阻断响应时间仅为184s,系统丢包率最小值为0.05,具有高效联动效果。

    Abstract:

    The complexity and variability of the network environment make it difficult for systems to detect abnormal behavior or attacks in a timely manner, and the linkage system between different devices cannot effectively achieve data sharing, which makes the network security device linkage system unable to effectively respond to new malicious attacks, resulting in long blocking response time and high packet loss rate. Therefore, in order to improve the security of the network, a network security device linkage system based on echo state network recognition was designed. In the hardware design of the network security device linkage system, an open interface approach is adopted to connect independent firewalls, intrusion detection systems, and other devices through interfaces, achieving information sharing and ensuring effective linkage. NetFlow Collector, Apache Spark, and Snort processing modules are used for information collection, processing, and detection. Then, through the Cobalt Strike device linkage decision-making device, trigger the linkage control mechanism, and use the WatchGuard linkage control platform to achieve network device linkage defense. In software design, to improve the accuracy of anomaly detection, an echo state network is introduced in the Snort processing module to carry out anomaly detection of various device data. Finally, based on the detection results, an improved FUP algorithm is used in the Cobalt Strike device for network security event correlation mining to discover potential attack information and submit it to the policy decision point of the decision-making layer for policy triggering. The policy triggering is completed by retrieving the corresponding processing strategy. Finally, the policy decision point issues the security event processing strategy command to the WatchGuard linkage control platform, thereby completing the linkage operation. According to the test results, the overall blocking response time of the system is only 184s, and the minimum packet loss rate of the system is 0.05, indicating an efficient linkage effect.

    参考文献
    相似文献
    引证文献
引用本文

梁雄,杨煊,梁才志.基于回声状态网络识别的网络安全设备联动系统设计计算机测量与控制[J].,2026,34(2):135-142.

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-04-16
  • 最后修改日期:2024-06-19
  • 录用日期:2025-03-06
  • 在线发布日期: 2026-02-09
  • 出版日期:
文章二维码