Statistic and Analysis for Host-Based Syslog

Zhaojun Gu, Wang Chao · 2010

Syslog audit acts an important role in keeping host secure. This paper studied Host-based syslog, and constructed a secure state model for host performing normally from the angle of anomaly detection. Through deep research on syslog protocol, a log collection tool was created for collecting remote or local host syslog. Because different segments of syslog imply different system information, the model separated every segment from a syslog record with Regular Expression, then it made data preprocessing and statistic with rule matching, in the end it conducted analysis by BP (Back Propagation) NN (Neural Network). The result indicates that not only can it achieve Host-based intrusion and anomaly detection, but also it is a high efficient and intelligent method.

Read the paper · More papers on PaperTik