System log clustering approaches for cyber security applications: A survey

Подходы к кластеризации системных журналов для приложений в области кибербезопасности: обзор
Max Landauer, Florian Skopik, Markus Wurzenberger, Andreas Rauber
2020-01-31

anomaly detectioncyber securitylog parsingsignature extractionsystem log clustering
Log files give insight into the state of a computer system and enable the detection of anomalous events relevant to cyber security. However, automatically analyzing log data is difficult since it contains massive amounts of unstructured and diverse messages collected from heterogeneous sources. Therefore, several approaches that condense or summarize log data by means of clustering techniques have been proposed. Picking the right approach for a particular application domain is, however, non-trivial, since algorithms are designed towards specific objectives and requirements. This paper therefore surveys existing approaches. It thereby groups approaches by their clustering techniques, reviews their applicability and limitations, discusses trends and identifies gaps. The survey reveals that approaches usually pursue one or more of four major objectives: overview and filtering, parsing and signature extraction, static outlier detection, and sequences and dynamic anomaly detection. Finally, this paper also outlines a concept and tool that support the selection of appropriate approaches based on user-defined requirements.
1
Log-clustering methods primarily pursue four objectives: overview and filtering, parsing and signature extraction, static outlier detection, and sequence-based dynamic anomaly detection.
2
System log clustering is valuable for cybersecurity because logs expose system state and support anomalous-event detection, but heterogeneous, massive, unstructured messages make automated analysis difficult.
3
The survey organizes existing log-clustering approaches by clustering technique and evaluates their applicability, limitations, trends, and research gaps.
4
The survey presents a concept and tool for selecting suitable log-clustering approaches according to user-defined application requirements.

system log clustering approaches for cybersecurity applications

the clustering techniques, applicability, limitations, trends, gaps, and objectives of approaches for condensing and analyzing heterogeneous log data, including overview and filtering, parsing and signature extraction, static outlier detection, and sequence-based dynamic anomaly detection

Publication Details
Publication Date
2020-01-31
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Max Landauer
Florian Skopik
Markus Wurzenberger
Andreas Rauber
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%