Semantic Mediation for A Posteriori Log Analysis - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Semantic Mediation for A Posteriori Log Analysis

Résumé

The a posteriori access control mode consists in monitoring actions performed by users, to detect possible violations of the security policy and to apply sanctions or reparations. In general, logs are among the first data sources that information security specialists consult for forensics when they suspect that something went wrong. One difficult challenge we face when analyzing logs, is the multiple log file formats. However, normalizing logs in one format needs a lot of processing especially because log files usually contain a high volume of data. Our study proposes then to tackle this problem, by leaving the different log formats as they are, and retrieving information from logs by querying them. A semantic mediator makes it possible to inter-operate various sources of information without modifying their internal functioning. It can be responsible for locating data sources, to transmit queries to each source, or from one source to another, to retrieve the queries responses and possibly send them back to other sources. To the best of our knowledge, semantic mediation techniques have been used to share information from heterogeneous data sources, but they were never used in the context of log analysis.
Fichier principal
Vignette du fichier
ARES__SEMANTIC_MEDIATION.pdf (798.68 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02497184 , version 1 (13-05-2020)

Identifiants

Citer

Farah Dernaika, Nora Cuppens-Boulahia, Frédéric Cuppens, Olivier Raynaud. Semantic Mediation for A Posteriori Log Analysis. ARES ’19, Aug 2019, Canterbury, United Kingdom. ⟨10.1145/3339252.3340104⟩. ⟨hal-02497184⟩
78 Consultations
122 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More