摘要:
给出了一个以日志分析为基础、结合关联规则与联动技术的安全事件管理系统(SYMCLOG)的框架及其实现,分析了日志处理的关联规则,根据日志数据的特点,结合数据挖掘技术对日志挖掘的Apriori算法进行了优化和改进,提高了SYMCLOG系统的实时响应能力与联动性,探讨了如何根据日志的处理结果进行事件的联动。
关键词:
日志分析,
关联规则,
SYMCLOG,
联动
Abstract: This paper analyses the technologies of event management system based on log and gives out the realization frame. It focuses on analyzing association rules of log disposition. And according to the characteristics of log, it optimizes log data mining algorithm——Apriori algorithm with the technology of data mining, which improves the interaction, security and real-time responsibility of the system. It also probes into the event interaction based on the result of handling log.
Key words:
log analysis,
association rule,
SYMCLOG,
interaction
中图分类号:
余亚玲;唐红武;杜海霞. 基于日志的安全事件管理系统的研究与实现[J]. 计算机工程, 2007, 33(16): 128-129,.
YU Ya-ling; TANG Hong-wu; DU Hai-xia. Research and Implementation of Security Event Management System Based on Log[J]. Computer Engineering, 2007, 33(16): 128-129,.