CiteULike is a free online bibliography manager. Register and you can start organising your references online.

Applying Information Retrieval Techniques to Event Log Analysis for Intrusion Detection Export

(8 January 2004)

Citation Format

[Posts]

View FullText article


cmalek's tags for this article

administration analysis anomaly bayes detection logging probability syslog systems unix

X Reviews [Write a review of this article]

X Notes for this article

cmalek has 0 private notes and 1 public note for this article.

Good article, has a bit of an overview on anomaly detection software. This is basically data mining meets syslog -- use a distance measure based on word frequency in syslog messages; higher distance == more rare.

cmalek (public note) - 2005-02-23 20:38:28

X Find related articles from these CiteULike users

X Find related articles with these CiteULike tags

X Posting History

X Abstract

This paper explores the application of probabilistic information retrieval theories to the field of log analysis and host-based intrusion detection. Strong similarities exist between intrusion detection and information retrieval. Using information retrieval techniques may yield significant improvements to the performance of intrusion detection systems. This paper provides a brief review of current relevant research in intrusion detection and log analysis, introduces information retrieval methods appropriate for intrusion detection, and proposes a framework for an experimental log analysis system. The proposed system is based on Bayesian probability theory and uses a term frequency-inverse document frequency (TF-IDF) measure to identify anomalies.


X BibTeX record

X RIS record


Privacy Statement | Terms & Conditions
CiteULike organises scholarly (or academic) papers or literature and provides bibliographic (which means it makes bibliographies) for universities and higher education establishments. It helps undergraduates and postgraduates. People studying for PhDs or in postdoctoral (postdoc) positions. The service is similar in scope to EndNote or RefWorks or any other reference manager like BibTeX, but it is a social bookmarking service for scientists and humanities researchers.