Potential threats mining methods based on correlation analysis of multi-type logs

Potential threats mining methods based on correlation analysis of multi-type logs
复制标题

基于多类型日志关联分析的潜在威胁挖掘方法

DOI:
10.1049/iet-net.2017.0188
复制
发表时间:
2017-12
期刊:
影响因子:
1.4
通讯作者:
Chenxu Wang
Chenxu Wang
中科院分区:
--
文献类型:
--
作者:
Tao Qin;Yuli Gao;Lingyan Wei;Zhaoli Liu;Chenxu Wang

文献摘要

参考文献

被引文献

相似文献

日志分析是通过仔细检查操作系统和设备记录的事件来检测威胁的有效方法。然而,由于海量的日志和各种格式的日志,准确发现威胁的难度越来越大。针对这一问题,提出了一种基于多类型日志相关性分析的潜在威胁挖掘方法。首先,根据已知攻击和潜在攻击的特征,从多类型日志中提取12个特征,包括行为相关特征、属性相关特征和可测量特征。他们还提出了归一化方法来处理这些异构性特征。其次,针对分析单一类型日志只能检测到特定攻击的问题,采用Logistic回归模型对多类型日志进行相关性分析。最后,构建了一个结合并行处理机制的异常检测平台,对海量记录进行处理。基于收集到的日志的实验结果表明,该方法具有较高的检测准确率和较低的计算复杂度,可用于从实际网络环境中的海量日志中挖掘潜在威胁和异常用户。
Log analysis is an efficiency way to detect threats by scrutinizing the events recorded by the operating systems and devices. However, it is more and more difficult to discover threats accurately due to the massive amount of logs and their various formats. Focusing on this problem, the authors propose a method for potential threats mining based on the correlation analysis of multi-type logs. Firstly, they extract 12 features, including behavior-related, attribute-related and measurable features, from multi-type logs based on the characteristics of known and potential attacks. They also propose normalization method to deal with these heterogeneous features. Secondly, focusing on solving the problem that analyzing a single type of log can only detect some specific attacks, they employ the logistic regression model to perform correlation analysis on multi-type logs. Finally, they construct an anomaly detection platform integrated with parallel processing mechanism to process the massive records. The experimental results based on logs collected show that the proposed method has high detection accuracy and low computational complexity, which can be applied to mine potential threats and abnormal users from the massive logs in an actual network environment.
DOI: 10.1109/ccis.2016.7790283
发表时间: 2016-08
期刊: 2016 4th International Conference on Cloud Computing and Intelligence Systems (CCIS)
影响因子: --
作者:
Jing Yu;Dan Tao;Zhaowen Lin
通讯作者: Jing Yu;Dan Tao;Zhaowen Lin
DOI: 10.1016/j.procs.2017.05.072
发表时间: 2017
期刊: --
影响因子: --
作者:
Jing Ya;Tingwen Liu;Quangang Li;Jinqiao Shi;Haoliang Zhang;Pin Lv;Li Guo
通讯作者: Jing Ya;Tingwen Liu;Quangang Li;Jinqiao Shi;Haoliang Zhang;Pin Lv;Li Guo
DOI: 10.1016/s1353-4858(09)70090-x
发表时间: 2009-07
期刊: Network Security archive
影响因子: --
作者:
Dario V. Forte
通讯作者: Dario V. Forte
DOI: 10.1016/j.cose.2017.03.003
发表时间: 2017-06
期刊: Comput. Secur.
影响因子: --
作者:
Blake D. Bryant;H. Saiedian
通讯作者: Blake D. Bryant;H. Saiedian
DOI: 10.1109/ntms.2014.6814006
发表时间: 2014-05
期刊: 2014 6th International Conference on New Technologies, Mobility and Security (NTMS)
影响因子: --
作者:
Antti Juvonen;T. Hämäläinen
通讯作者: Antti Juvonen;T. Hämäläinen