Big-Data Analysis of Multi-Source Logs for Anomaly Detection on Network-based System

被引:0
|
作者
Jia Zhanpei [1 ]
Shen Chao [1 ,2 ]
Yi Xiao [1 ]
Chen Yufei [1 ]
Yu Tianwen [1 ]
Guan Xiaohong [1 ]
机构
[1] Xi An Jiao Tong Univ, Xian 710049, Shaanxi, Peoples R China
[2] MOE Key Lab Intelligent Networks & Network Secur, Xian, Shaanxi, Peoples R China
基金
中国博士后科学基金; 中国国家自然科学基金;
关键词
FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Log data are important audit basis to record routine events occurring on computer or network system, which are also critical data source for detecting system anomalies. By analyzing the data from multi-source logs, it is helpful to detect abnormal system behaviors and discover intruder attacks in real time. In this paper, a Spark-based log data security platform is designed and built to analyze the large-scale log data and detect abnormal network behaviors. By integrating data mining, machine learning, and statistical analysis technologies, our proposed framework can quickly analyze large-scale multi-source log data and accurately discriminate the abnormal behaviors. Furthermore, the association analysis is applied to detect abnormal behaviors or potential threats in the system. Under a real-world network environment, extensive experiments are conducted to evaluate the system performance, which can achieve a fast and accurate detection for abnormal network behaviors, and significantly improve the accuracies under various types of network attack scenarios.
引用
收藏
页码:1136 / 1141
页数:6
相关论文
共 50 条
  • [1] Automated Analysis of Multi-source Logs for Network Forensics
    Chen Lin
    Li Zhitang
    Gao Cuixia
    PROCEEDINGS OF THE FIRST INTERNATIONAL WORKSHOP ON EDUCATION TECHNOLOGY AND COMPUTER SCIENCE, VOL I, 2009, : 660 - 664
  • [2] Approach to Anomaly Detection in Microservice System with Multi-Source Data Streams
    ZHANG Qixun
    HAN Jing
    CHENG Li
    ZHANG Baisheng
    GONG Zican
    ZTECommunications, 2022, 20 (03) : 85 - 92
  • [3] Multi-source data based anomaly detection through temporal and spatial characteristics
    Xu, Peng
    Gao, Qihong
    Zhang, Zhongbao
    Zhao, Kai
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 237
  • [4] Intelligent Visualization System for Big Multi-source Medical Data Based on Data Lake
    Ren, Peng
    Mao, Ziyun
    Li, Shuaibo
    Xiao, Yang
    Ke, Yating
    Yao, Lanyu
    Lan, Hao
    Li, Xin
    Sheng, Ming
    Zhang, Yong
    WEB INFORMATION SYSTEMS AND APPLICATIONS (WISA 2021), 2021, 12999 : 706 - 717
  • [5] Detecting Anomaly in Big Data System Logs Using Convolutional Neural Network
    Lu, Siyang
    Wei, Xiang
    Li, Yandong
    Wang, Liqiang
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 151 - 158
  • [6] Network threat detection based on correlation analysis of multi-platform multi-source alert data
    Xindai Lu
    Jiajia Han
    Qianbo Ren
    Hua Dai
    Jiyuan Li
    Jing Ou
    Multimedia Tools and Applications, 2020, 79 : 33349 - 33363
  • [7] Medical information management system based on multi-source heterogeneous big data
    Liu, Yiwen
    Li, Xinling
    Yu, Dequan
    Xu, Yangchao
    COMPUTER METHODS IN BIOMECHANICS AND BIOMEDICAL ENGINEERING-IMAGING AND VISUALIZATION, 2024, 12 (01):
  • [8] Network threat detection based on correlation analysis of multi-platform multi-source alert data
    Lu, Xindai
    Han, Jiajia
    Ren, Qianbo
    Dai, Hua
    Li, Jiyuan
    Ou, Jing
    MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (45-46) : 33349 - 33363
  • [9] Anomaly Location Model for Aircraft Intensity Detection Based on Multi-source Data Fusion
    Chen, Jiaojiao
    Chang, Liang
    Nie, Xiaohua
    Luo, Lilong
    2023 ASIA-PACIFIC INTERNATIONAL SYMPOSIUM ON AEROSPACE TECHNOLOGY, VOL II, APISAT 2023, 2024, 1051 : 1478 - 1489
  • [10] A DYNAMIC CLOUD BAYES NETWORK-BASED CLEANING METHOD OF MULTI-SOURCE UNSTRUCTURED DATA
    Yin Chao
    Liao Xinian
    Li Xiaobin
    PROCEEDINGS OF ASME 2022 17TH INTERNATIONAL MANUFACTURING SCIENCE AND ENGINEERING CONFERENCE, MSEC2022, VOL 2, 2022,