首页> 外文期刊>Future generation computer systems >Contextual filtering and prioritization of computer application logs for security situational awareness
【24h】

Contextual filtering and prioritization of computer application logs for security situational awareness

机译:用于安全态势认识的计算机应用程序日志的上下文过滤和优先级

获取原文
获取原文并翻译 | 示例

摘要

Critical computer systems strongly rely on event logs to record the occurrence of normative and anomalous events occurring at runtime. In spite of the advances in Security Information and Event Management for handling monitoring data in production, event logs remain quite underutilized with respect to more conventional security data sources. Eliciting actionable knowledge for situational awareness poses many challenges in the case of logs emitted by industrial systems due to the lack of standard practices, formats and threat models. This paper addresses log analysis in a critical industrial system. We conduct our study with a real-life system by a top leading company in the Air Traffic Control domain, which emits massive volumes of unstructured proprietary logs. We propose a filtering method that pinpoints interesting events from logs, i.e., events that should be followed up by analysts. Experiments are done with logs from normative and misuse scenarios; moreover, we compare the outcome of our method with a reference filtering technique based on the conceptual clustering. Results indicate that the proposed method is effective to retain interesting events at remarkable precision and recall and to pinpoint misuse indicators. We overcome several drawbacks of existing filtering techniques, such as the need for labeled logs and domain knowledge, which makes our method easier to use by practitioners.
机译:关键计算机系统强烈依赖事件日志,以记录运行时发生的规范性和异常事件的发生。尽管安全信息和事件管理的进展,用于处理生产中的监测数据,但事件日志对更传统的安全性数据源进行了很大限度。由于缺乏标准实践,格式和威胁模型,在工业系统发出的情况下,引发可行的态势意识的挑战造成许多挑战。本文解决了关键工业系统中的日志分析。我们在空中交通管制域中的一家领先的公司与现实寿命系统进行了研究,它发出了大量的非结构化专有日志。我们提出了一种过滤方法,可以从日志,即应由分析师跟踪的事件中查询有趣的事件。使用规范和误用方案的日志完成实验;此外,我们将通过基于概念聚类的参考滤波技术进行比较我们的方法的结果。结果表明,该方法可有效地保留有趣的精度和召回并查明滥用指标。我们克服了现有过滤技术的几个缺点,例如需要标记的日志和域知识,这使得我们的方法更容易被从业者使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号