首页> 外文会议>IEEE Military Communications Conference >An automatic approach to extract the formats of network and security log messages
【24h】

An automatic approach to extract the formats of network and security log messages

机译:一种自动提取网络和安全日志消息格式的方法

获取原文

摘要

Analyzing massive network and security logs that record network events is crucial for diagnosing network anomalies in large-scale network environments. Extracting log message formats is an important and necessary step to achieve the goal. However, it is time-consuming and costly to automatically and efficiently extract log message formats from massive network and security logs of many different types, which are generated by the increasing number of network and security devices and services used in large-scale networks. In this paper, we propose log template extraction (LTE), an approach that is semantics aware of network and security logs to address the problem. LTE first cleans log messages and then clusters the cleaned log messages based on the DBSCAN algorithm. At last it infers message templates by LDA Gibbs sampling algorithm. We evaluate our work on massive amount of network log messages collected from a large production network. Experimental results show that LTE approach infers and gets multiple log message formats at the same time with more than 90% accuracy and 100% recall.
机译:分析大型网络和记录网络事件的安全日志对于诊断大型网络环境中的网络异常至关重要。提取日志消息格式是实现该目标的重要且必要的步骤。但是,从大规模网络和许多不同类型的安全日志中自动有效地提取日志消息格式既费时又昂贵,这是由越来越多的网络以及在大型网络中使用的安全设备和服务生成的。在本文中,我们提出了日志模板提取(LTE),这是一种语义上了解网络和安全日志以解决该问题的方法。 LTE首先清除日志消息,然后根据DBSCAN算法对清除后的日志消息进行群集。最后,它通过LDA Gibbs采样算法推断出消息模板。我们根据从大型生产网络收集的大量网络日志消息来评估我们的工作。实验结果表明,LTE方法可同时推断并获取多种日志消息格式,准确性超过90%,召回率超过100%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号