首页> 外文会议>Proceedings of the 44th Hawaii International Conference on System Sciences >Log-Based Distributed Security Event Detection Using Simple Event Correlator
【24h】

Log-Based Distributed Security Event Detection Using Simple Event Correlator

机译:使用简单事件关联器的基于日志的分布式安全事件检测

获取原文

摘要

Log event correlation is an effective means of detecting system faults and security breaches encountered in information technology environments. Centralized, database-driven log event correlation is common, but suffers from flaws such as high network bandwidth utilization, significant requirements for system resources, and difficulty in detecting certain suspicious behaviors. Distributed event correlation is often assumed to be superior, but no research effort has been made which quantitatively evaluates its advantages and disadvantages. This research presents a distributed event correlation system which performs security event detection, and evaluates it experimentally, compared with a centralized alternative. The comparison measures the value in distributed event correlation by considering network bandwidth utilization, detection capability and database query efficiency. The implementation of these advantages allows a 99% reduction of network syslog traffic in the low accountability case. In addition, the system detects every implemented malicious use case, with a low false positive rate.
机译:日志事件关联是检测信息技术环境中遇到的系统故障和安全漏洞的有效方法。集中式,数据库驱动的日志事件关联是常见的,但存在诸如网络带宽利用率高,对系统资源的重大要求以及难以检测某些可疑行为之类的缺陷。通常认为分布式事件相关性优越,但是还没有进行定量评估其优缺点的研究工作。这项研究提出了一种分布式事件关联系统,该系统执行安全事件检测,并与集中式替代方法进行实验评估。该比较通过考虑网络带宽利用率,检测能力和数据库查询效率来衡量分布式事件关联中的值。这些优势的实现使得在低问责制情况下的网络系统日志流量减少了99%。此外,系统会以较低的误报率检测每个已实施的恶意用例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号