and the false positive rate is too high. (2) The trivial alerts
generated from large scale network attacks (e.g. DDoS) are
very complex and the relationships among them are difficult
to determine. (3) The data type of alert events generated
from security sensors are very abundant, while there is a lack
of knowledge needed by alert processing, and automatically
acquiring these knowledge is rather difficult.
In this paper, we summarize the research progress of
network security situation awareness, propose a framework
for network security situation awareness based upon
knowledge discovery, and apply the framework to our
network security situation awareness system (Net-SSA). The
rest of this paper is organized as follows: Section 2
introduces the concepts and functionalities of network
security situation awareness and summarizes the related
work of the area; Section 3 proposes our framework for
network security situation awareness based on knowledge
discovery; Section 4 presents the experiment results, and
Section 5 concludes with some directions for future work.