Filtering events using clustering in heterogeneous security logs

Filtering events using clustering in heterogeneous security logs
复制标题

DOI:
10.3923/itj.2011.798.806
复制
发表时间:
2011-04
期刊:
Information Technology Journal
影响因子:
--
通讯作者:
Asif Iqbal Hajamydeen;N. Udzir;R. Mahmod;A. Ghani
Asif Iqbal Hajamydeen;N. Udzir;R. Mahmod;A. Ghani
中科院分区:
其他
文献类型:
--
作者:
Asif Iqbal Hajamydeen;N. Udzir;R. Mahmod;A. Ghani

文献摘要

被引文献

相似文献

日志文件是丰富的信息源,它展示了我们在日常工作中使用计算机系统时所执行的操作。在本研究中,我们专注于分析/隔离来自不同来源的日志,然后使用数据挖掘工具(Weka)对日志进行聚类,以过滤日志中不需要的条目,这将极大地帮助将来自不同日志的事件关联起来。不幸的是,解析异构日志以提取属性值变得非常繁琐,因为每种类型的日志都以专有格式存储。我们提出了一个框架,它能够解析和隔离各种日志,然后对日志进行集群,以识别和删除不需要的条目。涉及一系列日志的实验揭示了这样一个事实,即聚类具有以更高的精度对日志条目进行分组的能力,从而有助于正确识别要删除的条目。
Log files are rich sources of information exhibiting the actions performed during the usage of a computer system in our daily work. In this study we concentrate on parsing/isolating logs from different sources and then clustering the logs using data mining tool (Weka) to filter the unwanted entries in the logs which will greatly help in correlating the events from different logs. Unfortunately parsing heterogeneous logs to extract the attribute values becomes tedious, since every type of log is stored in a proprietary format. We propose a framework that has the ability to parse and isolate a variety of logs, followed by clustering the logs to identify and remove unneeded entries. Experiments involving a range of logs, reveals the fact that clustering has the capacity to group log entries with a higher degree of accuracy, thereby assisting to identify correctly the entries to be removed.