The associated methods based on causal relationship. this method is by comparing the results of the first occurrence of the alarm information behavior and the prerequisite of the next occurrence alarm information behavior. it is able to associate two alarm information accurately and flexibly. it not only can revel the causal relationship between the known attack scene alarm information, but also can adapt to change in the supply of attack mode, to find unknown attack scenarios. at the same time Super alarms associated graph can also be intuitive reproduce the attack scene. the disadvantage of this method lies in the definition of the causal relationship is too complex, that it was just an off-line testing, apply it to real-time analysis of the association to be studied. and the establishment of the knowledge base can be achieved through manual intervention. it needs to have a full understanding of a variety of attack methods,and to continue to update the knowledge base.