Time Stamp Synchronization of Distributed Sensor Logs : Impossibility Results and Approximation Algorithms
Time Stamp Synchronization of Distributed Sensor Logs : Impossibility Results and Approximation Algorithms
复制标题
DOI:
--
复制
发表时间:
2005
期刊:
影响因子:
--
通讯作者:
Thomas Ristenpart
中科院分区:
文献类型:
--
作者:
Thomas Ristenpart
Heterogenous, distributed sensor systems utilize individual sensors (e.g ., IDSs, firewalls, and honeypots) that forward alerts to a central location where they are a gg gated into log files. Included in alerts are time stamps that record when the sensors observed th e alert-triggering behavior. When the system clocks of the sensors are not synchronized, temporal relationships among alerts cannot be directly determined from the time stamps. This impedes any usef ul analysis of the alert data since even simple temporal relationships such as order might be un recoverable. Although practitioners have reported repeatedly dealing with such situations, no gen eral solutions to this problem have been explored when a priori synchronization mechanisms (e.g., N TP) are unavailable or misconfigured. This work investigates a completely general mechanism for s ynchronizing the time stamps of collected alerts using only the data available in the log files. We show tha t general, precise a posteriori synchronization is impossible, but that simple approximation h euristics work well in realistic settings.