Aller au contenu principal
2022 conference-paper

LogTracer: Efficient Anomaly Tracing Combining System Log Detection and Provenance Graph

4Citations signalées, ce qui n’est pas une note de qualité
3Institutions déclarées
2Pays d’affiliation déclarés

Rattachement africain : cn, us. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

Information systems have penetrated into all areas of social life, however, unknown threats represented by APT attacks pose serious challenges to their security. In recent years, approaches based on log analysis and provenance graph have been extensively used in the anomaly detection and tracing of malicious attacks. However, traditional method has low detection accuracy, high complexity and low efficiency. To address those shortcomings, we propose an efficient anomaly tracing approach (LogTracer), which combines system log detection and provenance graph together. The proposed LogTracer extracts the attack path from provenance graph, which is constructed with the anomaly degrees of the system logs anomaly detection results. Compar-ative experiments with OmegaLog, NoDoze and ALchemist are conducted on a simulated dataset with 16 attack types totaling 290 million logs. The experimental results show that our method approximately 5.4x, 0.2x and 7.2x faster than these three methods in processing efficiency, and its malicious node coverage rate reaches 98.1%.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
LogTracer: Efficient Anomaly Tracing Combining System Log Detection and Provenance Graph
Date Crossref
04/12/2022
Éditeur
IEEE
Type
proceedings-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Où se fait cette recherche

  • University of Electronic Science and Technology of China pays non établi dans la notice
    Université ou école supérieure
  • Sichuan University pays non établi dans la notice
    Université ou école supérieure
  • NSK (United States) pays non établi dans la notice
    Entreprise
  • School of Computer Science and Engineering pays non établi dans la notice
    Université ou école supérieure
  • School of Cyber Science and Engineering pays non établi dans la notice
    Université ou école supérieure
  • Ltd. NSFOCUS Technologies Group Co. pays non établi dans la notice
    Entreprise

University of Electronic Science and Technology of China, Sichuan University et NSK (United States), avec 3 autres affiliations.

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Software System Performance and ReliabilityNetwork Security and Intrusion DetectionAnomaly Detection Techniques and Applications

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.