Log Analysis-Based Intrusion Detection via Unsupervised Learning
Pingchuan Ma · 2003
Keeping networks secure has never been such an imperative task as today. Threats come from hardware failures, software flaws, tentative probing and malicious attacks. Analyzing network logs to detect suspicious activities is one form of defense. However, the sheer size of network logs makes human log analysis intractable. Furthermore, traditional intrusion detection methods based on pattern-matching techniques cannot cope with the need for faster speed to manually update those patterns.