Enterprise Wide Centralized Logging Mechanism for Application Level Intrusion Detection.
Riaz Ahmed Shaikh, Saeed Rajput, Syed Mohammad Hassan Zaidi, Kashif Shairf · UEA Digital Repository (University of East Anglia) · 2005
Due to increase in occurrences of intrusion events, organizations are now moving towards implementation of various types of monitoring systems to detect and prevent IT security breaches. For that purpose, different techniques have been used. Logging is one of such technique. Typical enterprise consists of firewalls, intrusion detection systems, operating systems, legacy applications etc, where each element uses its own conventions and formats of logs. It increases the complexity in comprehensive analysis of logs to generate real time alerts and it also increases time to conduct forensic analysis. In this paper we have presented the concept of application level unification of logs in a consistent format at centralized locations to detect and prevent real time or near real time intrusions in a cost effective manner.