A Graph Database-Based Approach to Analyze Network Log Files

被引:6
|
作者
Diederichsen, Lars [1 ]
Choo, Kim-Kwang Raymond [2 ]
Le-Khac, Nhien-An [3 ]
机构
[1] German Fed Police, Potsdam, Germany
[2] Univ Texas San Antonio, San Antonio, TX 78249 USA
[3] Univ Coll Dublin, Sch Comp Sci, Dublin, Ireland
来源
关键词
Network log analysis; Graph database; Real-time analysis; Network security;
D O I
10.1007/978-3-030-36938-5_4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network log files from different sources often need to be analyzed in order to facilitate a more accurate assessment of the cyber threat severity. For example, using command line tools, any log file can be reviewed only in isolation. While using a log management system allows for searching across different log files, the relationship(s) between different network activities may not be easy to establish from the analysis of these different log files. We can use relational databases to establish these relationships, for example using complex database queries involving multiple join operations to link the tables. In recent years, there has been a trend of using graph databases to manage data for semantic queries (e.g. importing a fixed amount of log data for subsequent analysis). Hence, in this paper, we propose a new approach to analyze network log files, by using the graph database. Specifically, we posit the importance of constantly monitoring log files for new entries for immediate processed and analysis, and their results imported into the graph database. To facilitate the evaluation of our proposed approach, we use the Zeek network security monitor system to produce log files from monitored network traffic in real-time. We then explain how graph databases can be used to analyze network log files in near-real time within a network security-monitoring environment. Findings from our research demonstrate the utility of graph data in analyzing log data.
引用
收藏
页码:53 / 73
页数:21
相关论文
共 50 条
  • [21] An Approach Based on Contrast Patterns for Bot Detection on Web Log Files
    Loyola-Gonzalez, Octavio
    Monroy, Raul
    Angel Medina-Perez, Miguel
    Cervantes, Barbara
    Ernesto Grimaldo-Tijerina, Jose
    [J]. ADVANCES IN SOFT COMPUTING, MICAI 2018, PT I, 2018, 11288 : 276 - 285
  • [22] A grid-based approach for processing group activity log files
    Xhafa, Fatos
    Caballé, Santi
    Daradoumis, Thanasis
    Zhou, Nan
    [J]. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2004, 3292 : 175 - 186
  • [23] A grid-based approach for processing group activity log files
    Xhafa, F
    Caballé, S
    Daradoumis, T
    Zhou, N
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2004: OTM 2004 WORKSHOPS, PROCEEDINGS, 2004, 3292 : 175 - 186
  • [24] Validity of a Novel Institutional Method to Display and Analyze HeartMate II Log Files
    Holley, C.
    Pierce, C.
    Ambardekar, A.
    Allen, L. A.
    Brieke, A.
    Benton, E.
    Cleveland, J. C.
    Pal, J. D.
    [J]. JOURNAL OF HEART AND LUNG TRANSPLANTATION, 2018, 37 (04): : S264 - S265
  • [25] FACT - Database-based Analysis and Spectrum Calculations
    Schleicher, Bernd
    Arbet-Engels, A.
    Baack, D.
    Balbo, M.
    Biland, A.
    Bretz, T.
    Buss, J.
    Dorner, D.
    Eisenberger, L.
    Elsaesser, D.
    Hildebrand, D.
    Iotov, R.
    Kalenski, A.
    Mannheim, K.
    Mitchell, A.
    Neise, D.
    Noethe, M.
    Paravac, A.
    Rhode, W.
    Sliusar, V.
    Walter, R.
    [J]. 37TH INTERNATIONAL COSMIC RAY CONFERENCE, ICRC2021, 2022,
  • [26] An Effective Approach for Parsing Large Log Files
    Sedki, Issam
    Hamou-Lhadj, Abdelwahab
    Ait-Mohamed, Otmane
    Shehab, Mohammed A.
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME 2022), 2022, : 1 - 12
  • [27] Validity of a Novel Institutional Method to Analyze and Display HeartWare HVAD Log Files
    Lin, Y.
    Ambardekar, A.
    Allen, L. A.
    Pierce, C.
    Brieke, A.
    Benton, E.
    Cleveland, J. C.
    Pal, J. D.
    [J]. JOURNAL OF HEART AND LUNG TRANSPLANTATION, 2018, 37 (04): : S58 - S59
  • [28] A design methodology for semantic Web database-based systems
    Roldán-Garcia, MD
    Navas-Delgado, I
    Aldana-Montes, JF
    [J]. Third International Conference on Information Technology and Applications, Vol 1, Proceedings, 2005, : 233 - 237
  • [29] An Approach to Non-Relational Database-Based in the Storing of Heterogeneous Medical IoT Data
    Polat, Huseyin
    Oyucu, Saadin
    [J]. JOURNAL OF POLYTECHNIC-POLITEKNIK DERGISI, 2019, 22 (04): : 989 - 998
  • [30] Database-based archiving in the SAP R/3 system
    Schaarschmidt, R
    Roder, W
    [J]. WIRTSCHAFTSINFORMATIK, 1997, 39 (05): : 469 - &