期刊文献+

Event Normalization Through Dynamic Log Format Detection

Event Normalization Through Dynamic Log Format Detection
下载PDF
导出
摘要 The analytical and monitoring capabilities of central event re-positories, such as log servers and intrusion detection sys-tems, are limited by the amount of structured information ex-tracted from the events they receive. Diverse networks and ap-plications log their events in many different formats, and this makes it difficult to identify the type of logs being received by the central repository. The way events are logged by IT systems is problematic for developers of host-based intrusion-detection systems (specifically, host-based systems), develop-ers of security-information systems, and developers of event-management systems. These problems preclude the develop-ment of more accurate, intrusive security solutions that obtain results from data included in the logs being processed. We propose a new method for dynamically normalizing events into a unified super-event that is loosely based on the Common Event Expression standard developed by Mitre Corporation. We explain how our solution can normalize seemingly unrelat-ed events into a single, unified format. The analytical and monitoring capabilities of central event re-positories, such as log servers and intrusion detection sys-tems, are limited by the amount of structured information ex-tracted from the events they receive. Diverse networks and ap-plications log their events in many different formats, and this makes it difficult to identify the type of logs being received by the central repository. The way events are logged by IT systems is problematic for developers of host-based intrusion-detection systems (specifically, host-based systems), develop-ers of security-information systems, and developers of event-management systems. These problems preclude the develop-ment of more accurate, intrusive security solutions that obtain results from data included in the logs being processed. We propose a new method for dynamically normalizing events into a unified super-event that is loosely based on the Common Event Expression standard developed by Mitre Corporation. We explain how our solution can normalize seemingly unrelat-ed events into a single, unified format.
出处 《ZTE Communications》 2014年第3期62-66,共5页 中兴通讯技术(英文版)
关键词 event normalization: intrusion detection event stream processing knowledge base security information and event management event normalization: intrusion detection event stream processing knowledge base security information and event management
  • 相关文献

参考文献19

  • 1Guide to computer security log management, Technology Administration U. S. Department of Commerce, Sept. 2006.
  • 2Splunk Inc .. Splunk enterprise [Online). Avaiable: http://www.splunk.com/.
  • 3Hewlett- Packard. ArcSight logger [Online). http://www8.hp.com/us/en/software-solutions/arcsight-Iogger-Iog-managementl.
  • 4CS. Prelude IDS [Online). http://www.prelude-ids.com/enl.
  • 5EMC2. RSA envision [Online). http://emc.comlsecurity/rsa-envision.htm.
  • 6H.-P. ArcSight, 'Common Event Format," tech. rep., July 2009. Rev. 15.
  • 7The Incident Object Description Exchange Format, RFC 5070, Dec. 2007.
  • 8The Intrusion Detection, Message Exchange Format (IDMEF), RFC 4765, Mar. 2007.
  • 9A. Chuvakin, R. Marty, W. Heinbockel, J. Judge, and R. McQuaid, 'Common event expression," white paper, CEE Board, June 2008.
  • 10Formerly (SAL) [Online). https://hpi.de/meinel/security-tech/network-security/ security-analytics.html.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部