首页> 外文会议>International conference on networked systems >Efficient Security Policy Management Using Suspicious Rules Through Access Log Analysis
【24h】

Efficient Security Policy Management Using Suspicious Rules Through Access Log Analysis

机译:通过访问日志分析使用可疑规则进行有效的安全策略管理

获取原文

摘要

Logs record the events and actions performed within an organization's systems and networks. Usually, log data should conform with the security policy in use. However, access logs may show the occurrence of unauthorized accesses which may be due to security breaches, such as intrusions or conflicting rules in security policies. Due to the huge amount of log data generated every day and presumed to grow over time, analyzing access logs becomes a hard task that requires enormous computational resources. In this paper, we suggest a method that analyses an access log, and uses the obtained results to determine whether an Attribute-Based Access Control (ABAC) security policy contains conflicting rules. This access log-based approach allows to obtain an efficient conflict detection method, since conflicts are searched among suspicious rules, instead of all the rules of the policy. Those suspicious rules are identified by analyzing the access log. To improve efficiency even more, the access log is decomposed into clusters which are analyzed separately. Furthermore, cluster representatives make the proposed approach scalable for continuous access log case. The scalability is confirmed by experiment results, and our approach effectively identifies conflicts with an average recall of 95.65%.
机译:日志记录了在组织的系统和网络中执行的事件和操作。通常,日志数据应符合所使用的安全策略。但是,访问日志可能显示未经授权的访问的发生,这可能是由于安全漏洞(例如入侵或安全策略中的规则冲突)引起的。由于每天都会生成大量的日志数据,并且推测这些日志数据会随着时间的推移而增长,因此分析访问日志成为一项艰巨的任务,需要大量的计算资源。在本文中,我们建议一种分析访问日志并使用获得的结果确定基于属性的访问控制(ABAC)安全策略是否包含冲突规则的方法。这种基于访问日志的方法允许获得一种有效的冲突检测方法,因为冲突是在可疑规则而不是策略的所有规则中进行搜索的。通过分析访问日志来识别那些可疑的规则。为了进一步提高效率,将访问日志分解为单独分析的群集。此外,集群代表使所提出的方法可扩展用于连续访问日志的情况。实验结果证实了可扩展性,我们的方法有效地识别了冲突,平均召回率为95.65%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号