Taming the logs - Vocabularies for semantic security analysis

被引:9
|
作者
Ekelhart, Andreas [1 ]
Kiesling, Elmar [2 ]
Kurniawan, Kabul [2 ]
机构
[1] SBA Res, Favoritenstr 16, A-1040 Vienna, Austria
[2] TU Wien, Favoritenstr 9-11, A-1040 Vienna, Austria
基金
奥地利科学基金会;
关键词
semantic extraction; log vocabularies; log analysis; security analysis;
D O I
10.1016/j.procs.2018.09.011
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the growing complexity of information systems and the increasing prevalence and sophistication of threats, security management has become an enormously challenging task. To identify suspicious activities, security analysts need to monitor their systems constantly, which involves coping with high volumes of heterogeneous log data from various sources. Processes to aggregate these disparate logs and trigger alerts when particular events occur are often automated today. However, these methods are typically based on regular expressions and statistical correlations and do not involve any interpretation of the context in which an event occurred and do not allow for inference or sophisticated rules. Inspection and in-depth analysis of log information to link events from various sources (e.g., firewall, syslog, web server log, database log) and establish causal chains has therefore largely remained a tedious manual search process that scales poorly with a growing number of heterogeneous log sources, log volumes, and the increasing complexity of attacks. In this paper, we make the case for a semantic approach to tackle these challenges. By lifting raw log data and modeling their context, events can be linked to rich background knowledge, integrated based on causal relations, and interpreted in a context specific manner. This builds a foundation for more comprehensive extraction of the meaning of events from unstructured log messages. Based on the results, we envision a platform to partly automate security monitoring and support analysts in coping with fast evolving threat landscapes, alleviate alert fatigue, improve situational awareness, and expedite incidence response. (C) 2018 The Authors. Published by Elsevier B.V.
引用
收藏
页码:109 / 119
页数:11
相关论文
共 50 条
  • [1] Outsourcing security analysis with anonymized logs
    Zhang, Jianqing
    Borisov, Nikita
    Yurcik, William
    [J]. 2006 SECURECOMM AND WORKSHOPS, 2006, : 418 - +
  • [2] Linked Open Vocabularies (LOV): a gateway to reusable semantic vocabularies on the Web
    Vandenbussche, Pierre-Yves
    Atemezing, Ghislain A.
    Poveda-Villalon, Maria
    Vatant, Bernard
    [J]. SEMANTIC WEB, 2017, 8 (03) : 437 - +
  • [3] Summarizing Vocabularies in the Global Semantic Web
    Xiang Zhang
    Gong Cheng
    Wei-Yi Ge
    Yu-Zhong Qu
    [J]. Journal of Computer Science and Technology, 2009, 24 : 165 - 174
  • [4] Summarizing Vocabularies in the Global Semantic Web
    Zhang, Xiang
    Cheng, Gong
    Ge, Wei-Yi
    Qu, Yu-Zhong
    [J]. JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2009, 24 (01) : 165 - 174
  • [5] Summarizing Vocabularies in the Global Semantic Web
    张祥
    程龚
    葛唯益
    瞿裕忠
    [J]. Journal of Computer Science & Technology, 2009, 24 (01) : 165 - 174
  • [6] Using query logs to establish vocabularies in distributed information retrieval
    Shokouhi, Milad
    Zobel, Justin
    Tahaghoghi, Saied
    Scholer, Falk
    [J]. INFORMATION PROCESSING & MANAGEMENT, 2007, 43 (01) : 169 - 180
  • [7] Homomorphic Encryption atWork for Private Analysis of Security Logs
    Boudguiga, Aymen
    Stan, Oana
    Sedjelmaci, Hichem
    Carpov, Sergiu
    [J]. ICISSP: PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2020, : 515 - 523
  • [8] RDA Element Sets and RDA Value Vocabularies: Vocabularies for Resource Description in the Semantic Web
    Assumpcao, Fabricio Silva
    Santarem Segundo, Jose Eduardo
    Amorim da Costa Santos, Placida Leopoldina Ventura
    [J]. METADATA AND SEMANTICS RESEARCH, MTSR 2015, 2015, 544 : 147 - 158
  • [9] Empirically Evaluating the Semantic Qualities of Language Vocabularies
    Liaskos, Sotirios
    Mylopoulos, John
    Khan, Shakil M.
    [J]. CONCEPTUAL MODELING, ER 2021, 2021, 13011 : 330 - 344
  • [10] Semantic mediation of vocabularies for ocean observing systems
    Graybeal, John
    Isenor, Anthony W.
    Rueda, Carlos
    [J]. COMPUTERS & GEOSCIENCES, 2012, 40 : 120 - 131