Intelligent Log Analysis System for Massive and Multi-Source Security Logs: MMSLAS Design and Implementation Plan
Yizhen Sun, Shaoming Guo, Zhongwei Chen · 2019
In the Internet of Things and industrial controlnetwork servers, a large number of logs will be formed everymoment. This log information, as an important basis for eventrecording and security auditing, provides important informa-tion for identifying threat sources, identifying threat degreeand judging threat impact. However, the current security loganalysis system usually only standardizes the logs separately, and lacks the correlation analysis of the information fromvarious sources. Thus, this paper presents an intelligent loganalysis system for massive and multi-source security logs-MMSLAS(Massive and Multi-Source Security Log AnalysisSystem). In the log analysis module, the system integratesbusiness rule analysis and behavior analysis and additionallyadopts a machine learning-based analysis method, which fullyexploits the correlation between security logs and realizes thecomprehensive analysis of multi-source security logs. At thesame time, the distributed architecture scheme is also sufficientto cope with the system load caused by a large amount ofdata. The final implementation results show that MMSLAScan quickly locate the improper behavior in the log, and detectthe abnormal requests in advance according to the analysis ofthe behavior trajectory.