EVSec: An Approach to Extract and Visualize Security Scenarios from System Logs

Jameleddine Hassine · 2022

Logs, a.k.a. execution traces, provide a glimpse into the functionalities of running systems that have poor, incomplete, or outdated documentation. Logs contain a rich amount of information that can be used to facilitate troubleshooting/debugging, track events, detect security breaches, maintain regulatory requirements, and profile user behavior and workload. Driven by the growing complexity of today’s software platforms, reverse engineering of high-level models from system logs has gained momentum in recent years. In this paper, we introduce EVSec, an approach to extract and visualize security scenarios from system logs. The collected logs are first merged, filtered, labeled, and segmented into execution phases. The resulting phases are then visualized using the ITU-T standard, Use Case Maps (UCM) notation, extended with security annotations. We show the applicability of our proposed EVSec approach using two real-world security features, namely, Cisco IOS Login block and Cisco Unicast Reverse Path Forwarding (uRPF).

Read the paper · More papers on PaperTik