...
首页> 外文期刊>Information Technology Journal >Filtering Events using Clustering in Heterogeneous Security Logs
【24h】

Filtering Events using Clustering in Heterogeneous Security Logs

机译:使用异构安全日志中的群集过滤事件

获取原文
获取原文并翻译 | 示例
           

摘要

Log files are rich sources of information exhibiting the actions performed during the usage of a computer system in our daily work. In this study we concentrate on parsing/isolating logs from different sources and then clustering the logs using data mining tool (Weka) to filter the unwanted entries in the logs which will greatly help in correlating the events from different logs. Unfortunately parsing heterogeneous logs to extract the attribute values becomes tedious, since every type of log is stored in a proprietary format. We propose a framework that has the ability to parse and isolate a variety of logs, followed by clustering the logs to identify and remove unneeded entries. Experiments involving a range of logs, reveals the fact that clustering has the capacity to group log entries with a higher degree of accuracy, thereby assisting to identify correctly the entries to be removed.
机译:日志文件是丰富的信息源,显示了我们在日常工作中使用计算机系统期间执行的操作。在本研究中,我们着重于分析/隔离来自不同来源的日志,然后使用数据挖掘工具(Weka)对日志进行聚类以过滤日志中不需要的条目,这将极大地帮助关联来自不同日志的事件。不幸的是,由于每种类型的日志都以专有格式存储,因此解析异构日志以提取属性值变得乏味。我们提出了一个框架,该框架具有解析和隔离各种日志的能力,随后可以对日志进行聚类以识别和删除不需要的条目。涉及一系列日志的实验揭示了以下事实,即群集具有以较高的准确度对日志条目进行分组的能力,从而有助于正确识别要删除的条目。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号