Automation of Network Operations by Cooperation between Anomaly Detections and Operation Logs
Naoki Yoshida, Shingo Ata, Nakayama Hiroki, Tsunemasa Hayashi · 2017
Recently, network management becomes therefore more important to save a safe and secure ICT infrastructure. Since it is difficult to take appropriate actions against rapid, complicated, and diversed variation of behaviors in networking and service systems, conventional network management heavily relies on highly expertised operators. Automation of the management of ICT infrastructure is now a big challenging for future networks due to shortage of experts in network operations and management. In this paper, we propose a new framework for automating operations and management of ICT infrastructure, by combination of both networking/system incidents and records of operations. Our framework mainly focuses on the integration of various types of log data (e.g., alerts, flow analysis, access logs, command execution logs, etc.). As a proof of concept (PoC), we demonstrate an implementation of our framework by using honeypots and ssh-based agents.