Audit reduction and misuse detection in heterogeneous environments: framework and application
Paul E. Proctor · 2002
Audit data analysis is a non-invasive method for security assurance that may be used to detect computer misuse and mitigate security risks in large, distributed, open architecture environments. In most real-world environments, the heterogeneous nature of the available audit data combined with environment-specific detection requirements makes it difficult to integrate re-usable detection mechanisms in an effective audit analysis capability. This paper presents a framework for implementing audit reduction and intrusion detection in a heterogeneous environment with a re-usable set of detection mechanisms. Experimental results indicate that this framework brings order to the analysis process and demonstrates the efficacy of the framework for producing cohesive, intuitive audit reduction in a heterogeneous environment with a re-usable detection toolset.>