Log File Analysis with Context-Free Grammars

Abstract : Classical intrusion analysis of network log files uses statistical machine learning or regular expressions. Where statistically machine learning methods are not analytically exact, methods based on regular expressions do not reach up very far in Chomsky’s hierarchy of languages. This paper focuses on parsing traces of network traffic using context-free grammars. “Green grammars” are used to describe acceptable log files while “red grammars” are used to represent known intrusion patterns. This technique can complement or augment existing approaches by providing additional precision. Analytically, the technique is also more powerful than existing techniques that use regular expressions.
Type de document :
Communication dans un congrès
Gilbert Peterson; Sujeet Shenoi. 9th International Conference on Digital Forensics (DF), Jan 2013, Orlando, FL, United States. Springer, IFIP Advances in Information and Communication Technology, AICT-410, pp.145-152, 2013, Advances in Digital Forensics IX. 〈10.1007/978-3-642-41148-9_10〉
Liste complète des métadonnées

Littérature citée [10 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01460602
Contributeur : Hal Ifip <>
Soumis le : mardi 7 février 2017 - 17:25:41
Dernière modification le : vendredi 1 décembre 2017 - 01:16:43
Document(s) archivé(s) le : lundi 8 mai 2017 - 14:58:10

Fichier

978-3-642-41148-9_10_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Gregory Bosman, Stefan Gruner. Log File Analysis with Context-Free Grammars. Gilbert Peterson; Sujeet Shenoi. 9th International Conference on Digital Forensics (DF), Jan 2013, Orlando, FL, United States. Springer, IFIP Advances in Information and Communication Technology, AICT-410, pp.145-152, 2013, Advances in Digital Forensics IX. 〈10.1007/978-3-642-41148-9_10〉. 〈hal-01460602〉

Partager

Métriques

Consultations de la notice

63

Téléchargements de fichiers

58