Security audit analysis based on feature fusion
Yongbo Ma · Journal of Chongqing University of Posts and Telecommunications · 2006
Methods of traditional security audit analysis are introduced,but the related features of system logs and network data are not well considered in these methods.Suspicious security events are drawn through analyzing system logs.They are further investigated by fusing features of system logs and network data.Comparing the similarities of current security event with normal history event and abnormal history event respectively,abnormal suspicious event can be audited.Experiments indicated that this method is feasible.