![]() |
CiteULike | ![]() |
cmalek's CiteULike | ![]() |
![]() |
|
![]() |
Register | ![]() |
Log in | ![]() |
Applying Information Retrieval Techniques to Event Log Analysis for Intrusion Detectionby: John Reuning
|
Reviews
[Write a review of this article]
Notes for this articleGood article, has a bit of an overview on anomaly detection software. This is basically data mining meets syslog -- use a distance measure based on word frequency in syslog messages; higher distance == more rare.
Find related articles from these CiteULike users
Find related articles with these CiteULike tags
Posting History
AbstractThis paper explores the application of probabilistic information retrieval theories to the field of log analysis and host-based intrusion detection. Strong similarities exist between intrusion detection and information retrieval. Using information retrieval techniques may yield significant improvements to the performance of intrusion detection systems. This paper provides a brief review of current relevant research in intrusion detection and log analysis, introduces information retrieval methods appropriate for intrusion detection, and proposes a framework for an experimental log analysis system. The proposed system is based on Bayesian probability theory and uses a term frequency-inverse document frequency (TF-IDF) measure to identify anomalies.
BibTeX record
RIS record