A Graph Database-Based Approach to Analyze Network Log Files

被引:6
|
作者
Diederichsen, Lars [1 ]
Choo, Kim-Kwang Raymond [2 ]
Le-Khac, Nhien-An [3 ]
机构
[1] German Fed Police, Potsdam, Germany
[2] Univ Texas San Antonio, San Antonio, TX 78249 USA
[3] Univ Coll Dublin, Sch Comp Sci, Dublin, Ireland
来源
关键词
Network log analysis; Graph database; Real-time analysis; Network security;
D O I
10.1007/978-3-030-36938-5_4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network log files from different sources often need to be analyzed in order to facilitate a more accurate assessment of the cyber threat severity. For example, using command line tools, any log file can be reviewed only in isolation. While using a log management system allows for searching across different log files, the relationship(s) between different network activities may not be easy to establish from the analysis of these different log files. We can use relational databases to establish these relationships, for example using complex database queries involving multiple join operations to link the tables. In recent years, there has been a trend of using graph databases to manage data for semantic queries (e.g. importing a fixed amount of log data for subsequent analysis). Hence, in this paper, we propose a new approach to analyze network log files, by using the graph database. Specifically, we posit the importance of constantly monitoring log files for new entries for immediate processed and analysis, and their results imported into the graph database. To facilitate the evaluation of our proposed approach, we use the Zeek network security monitor system to produce log files from monitored network traffic in real-time. We then explain how graph databases can be used to analyze network log files in near-real time within a network security-monitoring environment. Findings from our research demonstrate the utility of graph data in analyzing log data.
引用
收藏
页码:53 / 73
页数:21
相关论文
共 50 条
  • [1] A graph database-based approach utilizing FAHP and directed bipartite graph for service composition
    Fan, Guodong
    Zhu, Ming
    Li, Jing
    Wang, Chun
    Zhao, Lei
    [J]. SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2020, 14 (04) : 269 - 281
  • [2] A graph database-based approach utilizing FAHP and directed bipartite graph for service composition
    Guodong Fan
    Ming Zhu
    Jing Li
    Chun Wang
    Lei Zhao
    [J]. Service Oriented Computing and Applications, 2020, 14 : 269 - 281
  • [3] Graph database-based network security situation awareness data storage method
    Xiaoling Tao
    Yang Liu
    Feng Zhao
    Changsong Yang
    Yong Wang
    [J]. EURASIP Journal on Wireless Communications and Networking, 2018
  • [4] Graph database-based network security situation awareness data storage method
    Tao, Xiaoling
    Liu, Yang
    Zhao, Feng
    Yang, Changsong
    Wang, Yong
    [J]. EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2018,
  • [5] Application of weaving based on log files in database systems
    Chen, Feng
    Chen, Bin
    Xu, Huan
    Yang, Qiuyong
    Zeng, Xiaowen
    [J]. International Journal of Data Science, 2024, 9 (3-4) : 183 - 202
  • [6] Comparing graph-based program comprehension tools to relational database-based tools
    Lange, C
    Sneed, HM
    Winter, A
    [J]. 9TH INTERNATIONAL WORKSHOP ON PROGRAM COMPREHENSION, PROCEEDINGS, 2001, : 209 - 218
  • [7] Database-Based Web Page
    Liang Dan xi 1
    2.E Commerce Application Development Architect
    [J]. Wuhan University Journal of Natural Sciences, 2001, (Z1) : 443 - 447
  • [8] A Practical Algorithm for DNA Pattern Searching using Database-Based Approach
    Kaniwa, Freeson
    Phuthego, Mpho
    [J]. PROCEEDINGS 2018 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE (BIBM), 2018, : 1484 - 1489
  • [9] Process, Analyze and Visualize Telecommunication Network Configuration Data in Graph Database
    Lehotay-Kery, Peter
    Kiss, Attila
    [J]. VIETNAM JOURNAL OF COMPUTER SCIENCE, 2020, 7 (01) : 65 - 76
  • [10] Passage Retrieval in Log Files: An Approach Based on Query Enrichment
    Saneifar, Hassan
    Bonniol, Stephane
    Laurent, Anne
    Poncelet, Pascal
    Roche, Mathieu
    [J]. ADVANCES IN NATURAL LANGUAGE PROCESSING, 2010, 6233 : 357 - +