Distributed audit trail analysis

Abdelaziz Mounji, Baudouin Le Charlier, Denis Zampunidris, Naji Habra

Résultats de recherche: Contribution dans un livre/un catalogue/un rapport/dans les actes d'une conférenceArticle dans les actes d'une conférence/un colloque

Résumé

An implemented system for on-line analysis of multiple distributed data streams is presented. The system is conceptually universal since it does not rely on any particular platform feature and uses format adaptors to translate data streams into its own standard format. The system is as powerful as possible (from a theoretical standpoint) but still efficient enough for on-line analysis thanks to its novel rule-based language (BUS-SEL) which is specifically designed for efficientpro-cessing of sequential unstructured data streams. In this paper, the generic concepts are applied to security audit trail analysis. The resulting system provides powerful network security monitoring and sophisticated tools for intrusion/anomaly detection. The rule-based and command languages are described as well as the distributed architecture and the implementation. Performance measurements are reported, showing the effectiveness of the approach.

langue originaleAnglais
titreProceedings of the Symposium on Network and Distributed System Security, NDSS 1995
EditeurInstitute of Electrical and Electronics Engineers Inc.
Pages102-112
Nombre de pages11
ISBN (Electronique)0818670274, 9780818670275
Les DOIs
Etat de la publicationPublié - 1 janv. 1995
Evénement1995 Symposium on Network and Distributed System Security, NDSS 1995 - San Diego, États-Unis
Durée: 16 févr. 199517 févr. 1995

Série de publications

NomProceedings of the Symposium on Network and Distributed System Security, NDSS 1995

Une conférence

Une conférence1995 Symposium on Network and Distributed System Security, NDSS 1995
PaysÉtats-Unis
La villeSan Diego
période16/02/9517/02/95

Empreinte digitale Examiner les sujets de recherche de « Distributed audit trail analysis ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation