Preprocessor for Complex Event Processing System in Network Security

被引:4
作者
Jayan, Keerthi [1 ]
Rajan, Archana K. [1 ]
机构
[1] Amrita Vishwa Vidyapeetham, Amrita Sch Engn, Comp Sci & Engn, Kollam, India
来源
2014 FOURTH INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING AND COMMUNICATIONS (ICACC) | 2014年
关键词
Network Security; CEP; Esper; Sys log; Risk taxonomy;
D O I
10.1109/ICACC.2014.52
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network security refers to any activity designed to protect the network. These activities intend to protect the usability, reliability, and safety of network and data. Effective network security targets a variety of threats and stops them from entering or spreading on network. In network security, Complex Event Processing (CEP) system can be used for correlating events across different security devices and applications for complicated attack detection and response. The events will be recorded in sys log files. There will be millions of events generated by each security device. Hence, the CEP engine has to process massive amount of logs. We describe a method for preprocessing the vast input to extract relevant data, the CEP engine shall be concerned about. The CEP engine which we used in this system is ESPER. The sys log is preprocessed based on risk taxonomy. Risk taxonomy is built in a hierarchical structure with respect to the attacks the CEP is looking for.
引用
收藏
页码:187 / 189
页数:3
相关论文
共 9 条
[1]  
Bhargavi R, 2011, INT J COMPUTER THEOR, V3
[2]  
Buchmann Alejandro, COMPLEX EVENT PROCES
[3]  
Chen H., 2005, KDD 05, P750
[4]  
Chen M. Y., 2004, P INT S NETW SYST DE, P309
[5]  
Cohen I., 2005, SIGOPS OPER SYST REV, V39
[6]  
Guo Z., 2006, DSN 06, P259
[7]  
Nicolett Mark, 2009, CRITICAL CAPABILITIE
[8]  
Sabato Sivan, ANAL SYSTEM LOGS NEW
[9]  
Zhang Jun, 2012, IEEE T PARALLEL DIST