计算机应用 ›› 2010, Vol. 30 ›› Issue (06): 1708-1710.

• 典型应用 • 上一篇    

综合安全管理平台中日志格式化系统的设计与实现

李扬1,王景中2,杨义先3   

  1. 1. 北方工业大学
    2. 北方工业大学 信息工程学院
    3. 北京邮电大学信息安全中心
  • 收稿日期:2009-12-28 修回日期:2010-02-18 发布日期:2010-06-01 出版日期:2010-06-01
  • 通讯作者: 李扬

Design and implementation of log format system in integrated network security management platform

  • Received:2009-12-28 Revised:2010-02-18 Online:2010-06-01 Published:2010-06-01

摘要: 为了提高日志格式化系统的执行效率以及解决无法解析日志时便丢弃日志的问题,提出了一种日志格式化方案。通过将设备、传输通道和插件三者绑定,避免了格式化过程中的查找判断过程。通过引入自动更新模块,使系统在无法解析日志时可以从插件库自动下载插件来完成格式化过程。最终的测试结果表明了该方案的可行性。

关键词: 综合安全管理平台, 日志, 日志格式化, 插件, 分布式拒绝服务攻击

Abstract: In order to improve the efficiency of log format system and to solve the problem that log is discarded if system can not recognize the log, a log format system scheme was proposed. In this scheme, the process of search and determination was avoided by binding equipment, port and plug. Through automatic update module, the log format system can download the corresponding plug from server when logs can not be recognized. Simulation tests show that this log format system scheme is completely feasible.

Key words: network security management platform, log, log format, plug, DDoS