Mining Host Behavior Patterns From Massive Network and Security Logs

Mining Host Behavior Patterns From Massive Network and Security Logs
复制标题

DOI:
10.1016/j.procs.2017.05.072
复制
发表时间:
2017
期刊:
--
影响因子:
--
通讯作者:
Jing Ya;Tingwen Liu;Quangang Li;Jinqiao Shi;Haoliang Zhang;Pin Lv;Li Guo
Jing Ya;Tingwen Liu;Quangang Li;Jinqiao Shi;Haoliang Zhang;Pin Lv;Li Guo
中科院分区:
其他
文献类型:
--
作者:
Jing Ya;Tingwen Liu;Quangang Li;Jinqiao Shi;Haoliang Zhang;Pin Lv;Li Guo

文献摘要

被引文献

相似文献

从海量日志中挖掘主机行为模式在大规模网络异常诊断和管理中具有重要而关键的作用。几乎所有的前人工作都给出了网络事件的宏观链接分析,但没有从微观上分析网络中每台主机的行为模式的演变。本文针对已有工作的局限性,提出了一种新的行为模式日志挖掘方法(LogM4BP)。LogM4BP利用非负矩阵分解算法建立统计模型,捕获每个主机的网络行为模式,最终提高行为模式的解释度和可比性,降低分析的复杂度。这项工作是根据从一家大型营销公司获得的公共数据集进行评估的。实验结果表明,该方法能够清晰、准确地描述网络行为模式,并能直观地将行为模式的显著演变映射到现实世界中的异常事件。
Mining host behavior patterns from massive logs plays an important and crucial role in anomalies diagnosing and management for large-scale networks. Almost all prior work gives a macroscopic link analysis of network events, but fails to microscopically analyze the evolution of behavior patterns for each host in networks. In this paper, we propose a novel approach, namely Log Mining for Behavior Pattern (LogM4BP), to address the limitations of prior work. LogM4BP builds a statistical model that captures each host’s network behavior patterns with the nonnegative matrix factorization algorithm, and finally improve the interpretation and comparability of behavior patterns, and reduce the complexity of analysis. The work is evaluated on a public data set captured from a big marketing company. Experimental results show that it can describe network behavior patterns clearly and accurately, and the significant evolution of behavior patterns can be mapped to anomaly events in real world intuitively.