首页> 外文会议>Network Operations and Management Symposium (NOMS), 2012 IEEE >A distance-based method to detect anomalous attributes in log files
【24h】

A distance-based method to detect anomalous attributes in log files

机译:基于距离的方法来检测日志文件中的异常属性

获取原文
获取原文并翻译 | 示例

摘要

Dealing with large volumes of logs is like the proverbial needle in the haystack problem. Finding relevant events that might be associated with an incident, or real time analysis of operational logs is extremely difficult when the underlying data volume is huge and when no explicit misuse model exists. While domain-specific knowledge and human expertise may be useful in analysing log data, automated approaches for detecting anomalies and track incidents are the only viable solutions when confronted with large volumes of data. In this paper we address the issue of automated log analysis and consider more specifically the case of ISP-provided firewall logs. We leverage approaches derived from statistical process control and information theory in order to track potential incidents and detect suspicious network activity.
机译:处理大量原木就像大海捞针中的谚语。当基础数据量巨大且不存在明确的滥用模型时,查找可能与事件相关的相关事件或对操作日志进行实时分析非常困难。尽管特定领域的知识和人员专长在分析日志数据时可能有用,但是当面对大量数据时,用于检测异常和跟踪事件的自动化方法是唯一可行的解​​决方案。在本文中,我们解决了自动日志分析的问题,并且更具体地考虑了ISP提供的防火墙日志的情况。我们利用从统计过程控制和信息理论派生的方法来跟踪潜在事件并检测可疑网络活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号