Syslog Episode Mining for Tracking Behavior in SCADA servers

Xiuzhe Yang, Jit Biswas, David K. Y. Yau, Ming Yu · 2022

It is important to assess the reliability of software upgrades and patches applied regularly to servers within SCADA systems. This paper introduces a top-down approach to characterize the degree of similarity between sets of episodes arising from server logs. Filtered sub-logs of syslog data are mined to check whether they contain base episodes. Subsequently higher-level compound episodes are mined, wherein multiple base episodes are composed into compound episodes, from possibly different source programs. A tracking score is used to assess changes in the similarity of the syslog over time-periods. Unexpected changes in tracking scores could indicate potential reliability concerns. Episode mining is suggested as a method to obtain the rules by which invariant-checking could be implemented, to continuously monitor a SCADA system's reliability during operation.

Read the paper · More papers on PaperTik