Complex log file synthesis for rapid sandbox-benchmarking of security- and computer network analysis tools. (August 2016)
- Record Type:
- Journal Article
- Title:
- Complex log file synthesis for rapid sandbox-benchmarking of security- and computer network analysis tools. (August 2016)
- Main Title:
- Complex log file synthesis for rapid sandbox-benchmarking of security- and computer network analysis tools
- Authors:
- Wurzenberger, Markus
Skopik, Florian
Settanni, Giuseppe
Scherrer, Wolfgang - Abstract:
- Abstract: Today Information and Communications Technology (ICT) networks are a dominating component of our daily life. Centralized logging allows keeping track of events occurring in ICT networks. Therefore a central log store is essential for timely detection of problems such as service quality degradations, performance issues or especially security-relevant cyber attacks. There exist various software tools such as security information and event management (SIEM) systems, log analysis tools and anomaly detection systems, which exploit log data to achieve this. While there are many products on the market, based on different approaches, the identification of the most efficient solution for a specific infrastructure, and the optimal configuration is still an unsolved problem. Today׳s general test environments do not sufficiently account for the specific properties of individual infrastructure setups. Thus, tests in these environments are usually not representative. However, testing on the real running productive systems exposes the network infrastructure to dangerous or unstable situations. The solution to this dilemma is the design and implementation of a highly realistic test environment, i.e. sandbox solution, that follows a different – novel – approach. The idea is to generate realistic network event sequence (NES) data that reflects the actual system behavior and which is then used to challenge network analysis software tools with varying configurations safely andAbstract: Today Information and Communications Technology (ICT) networks are a dominating component of our daily life. Centralized logging allows keeping track of events occurring in ICT networks. Therefore a central log store is essential for timely detection of problems such as service quality degradations, performance issues or especially security-relevant cyber attacks. There exist various software tools such as security information and event management (SIEM) systems, log analysis tools and anomaly detection systems, which exploit log data to achieve this. While there are many products on the market, based on different approaches, the identification of the most efficient solution for a specific infrastructure, and the optimal configuration is still an unsolved problem. Today׳s general test environments do not sufficiently account for the specific properties of individual infrastructure setups. Thus, tests in these environments are usually not representative. However, testing on the real running productive systems exposes the network infrastructure to dangerous or unstable situations. The solution to this dilemma is the design and implementation of a highly realistic test environment, i.e. sandbox solution, that follows a different – novel – approach. The idea is to generate realistic network event sequence (NES) data that reflects the actual system behavior and which is then used to challenge network analysis software tools with varying configurations safely and realistically offline. In this paper we define a model, based on log line clustering and Markov chain simulation to create this synthetic log data. The presented model requires only a small set of real network data as an input to understand the complex real system behavior. Based on the input׳s characteristics highly realistic customer specified NES data is generated. To prove the applicability of the concept developed in this work, we conclude the paper with an illustrative example of evaluation and test of an existing anomaly detection system by using generated NES data. Abstract : Highlights: Generating log data that reflects realistic network behavior. Log data modeling, based on log line clustering and Markov chain simulation. Rate, analyze and improve software tools, which exploit log data. Detailed evaluation of the model and presentation of an illustrative application. Cornerstones to improve the selection, deployment and operation of IDSs. … (more)
- Is Part Of:
- Information systems. Volume 60(2016)
- Journal:
- Information systems
- Issue:
- Volume 60(2016)
- Issue Display:
- Volume 60, Issue 2016 (2016)
- Year:
- 2016
- Volume:
- 60
- Issue:
- 2016
- Issue Sort Value:
- 2016-0060-2016-0000
- Page Start:
- 13
- Page End:
- 33
- Publication Date:
- 2016-08
- Subjects:
- Log line clustering -- Markov chains -- Log file analysis -- Log data modeling -- IDS deployment optimization
Database management -- Periodicals
Electronic data processing -- Periodicals
Bases de données -- Gestion -- Périodiques
Informatique -- Périodiques
Database management
Electronic data processing
Periodicals
005.7 - Journal URLs:
- http://www.sciencedirect.com/science/journal/03064379 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.is.2016.02.006 ↗
- Languages:
- English
- ISSNs:
- 0306-4379
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4496.367300
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 144.xml