首页> 外文会议>2011 17th IEEE International Conference on Parallel and Distributed Systems >Visualization System for Log Analysis with Probabilities of Incorrect Operation
【24h】

Visualization System for Log Analysis with Probabilities of Incorrect Operation

机译:具有错误操作可能性的日志分析可视化系统

获取原文

摘要

As advancement of information society, information leakages grow into a serious problem. It is important for security managers to analysis log-files for finding out cause of leakages promptly. Existing methods of presenting log-files take the method of ordering them in time. It makes easy to understand a flow of operations. However, if a log recording an incorrect operation is included in the back of log-file, finding out it may drop back. To address this problem, this paper presents visualization system for log analysis with probabilities of incorrect operation. Incorrect operations are operations that may cause a security incident. Probabilities of incorrect operation are set up by rate of number of incorrect operations in past log-files. Security analysts set order of priority, and logs are sorted. Also, we introduce Visualize Part to help security analysts understand a flow of operations in spite of not ordering logs in time. We aim to contribute speedy security analyses by combine visualizing log-file with probabilities of incorrect operation. To evaluate our proposal, accuracy and efficiency are measured by user experiment. Our proposal tool was compared with the tool without probabilities of incorrect operation. As the result, in terms of accuracy, there are no significant difference between. However, our proposal demonstrate a 39.5% improved efficiency.
机译:随着信息社会的发展,信息泄漏成为一个严重的问题。对于安全管理人员而言,分析日志文件以迅速找出泄漏原因非常重要。呈现日志文件的现有方法采用对它们进行及时排序的方法。它使操作流程易于理解。但是,如果记录错误操作的日志包含在日志文件的后面,则找出该日志可能会回退。为了解决这个问题,本文提出了用于日志分析的可视化系统,该系统具有错误操作的可能性。错误的操作是可能导致安全事故的操作。错误操作的可能性由过去的日志文件中错误操作的数量比率确定。安全分析人员设置优先级顺序,并对日志进行排序。另外,我们引入了Visualize Part,以帮助安全分析人员了解不按时排序日志的操作流程。我们的目标是通过结合可视化日志文件和错误操作的可能性来提供快速的安全性分析。为了评估我们的建议,我们通过用户实验来评估准确性和效率。我们将我们的提案工具与没有错误操作可能性的工具进行了比较。结果,就准确性而言,两者之间没有显着差异。但是,我们的建议表明效率提高了39.5%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号