Time Stamp Synchronization of Distributed Sensor Logs : Impossibility Results and Approximation Algorithms

Time Stamp Synchronization of Distributed Sensor Logs : Impossibility Results and Approximation Algorithms
复制标题

DOI:
--
复制
发表时间:
2005
期刊:
--
影响因子:
--
通讯作者:
Thomas Ristenpart
Thomas Ristenpart
中科院分区:
其他
文献类型:
--
作者:
Thomas Ristenpart

文献摘要

被引文献

相似文献

异构、分布式传感器系统利用单个传感器(例如:(如ids、防火墙和蜜罐),它们将警报转发到一个中心位置,在那里它们被关入日志文件。警报中包括记录传感器何时观察到警报触发行为的时间戳。当传感器的系统时钟不同步时,不能直接从时间戳确定警报之间的时间关系。这阻碍了对警报数据的任何有用分析,因为即使是简单的时间关系(如订单)也可能无法恢复。尽管从业者已经反复报告了处理这种情况,但是当先验的同步机制(例如,N - TP)不可用或配置错误时,还没有针对该问题的通用解决方案。本文研究了一种完全通用的机制,用于仅使用日志文件中可用的数据来同步所收集警报的时间戳。我们表明,一般的、精确的后验同步是不可能的,但这种简单的近似特征在现实环境中工作得很好。
Heterogenous, distributed sensor systems utilize individual sensors (e.g ., IDSs, firewalls, and honeypots) that forward alerts to a central location where they are a gg gated into log files. Included in alerts are time stamps that record when the sensors observed th e alert-triggering behavior. When the system clocks of the sensors are not synchronized, temporal relationships among alerts cannot be directly determined from the time stamps. This impedes any usef ul analysis of the alert data since even simple temporal relationships such as order might be un recoverable. Although practitioners have reported repeatedly dealing with such situations, no gen eral solutions to this problem have been explored when a priori synchronization mechanisms (e.g., N TP) are unavailable or misconfigured. This work investigates a completely general mechanism for s ynchronizing the time stamps of collected alerts using only the data available in the log files. We show tha t general, precise a posteriori synchronization is impossible, but that simple approximation h euristics work well in realistic settings.