Abstract
The integration of heterogeneous and weakly linked log data poses a major challenge in many log-analytic applications. Knowledge graphs (KGs) can facilitate such integration by providing a versatile representation that can interlink objects of interest and enrich log events with background knowledge. Furthermore, graph-pattern based query languages, such as SPARQL, can support rich log analyses by leveraging semantic relationships between objects in heterogeneous log streams. Constructing, materializing, and maintaining centralized log knowledge graphs, however, poses significant challenges. To tackle this issue, we propose VloGraph—a distributed and virtualized alternative to centralized log knowledge graph construction. The proposed approach does not involve any a priori parsing, aggregation, and processing of log data, but dynamically constructs a virtual log KG from heterogeneous raw log sources across multiple hosts. To explore the feasibility of this approach, we developed a prototype and demonstrate its applicability to three scenarios. Furthermore, we evaluate the approach in various experimental settings with multiple heterogeneous log sources and machines; the encouraging results from this evaluation suggest that the approach can enable efficient graph-based ad-hoc log analyses in federated settings.
Funder
FWF Austrian Science Fund
Subject
General Economics, Econometrics and Finance
Reference60 articles.
1. Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Managementhttps://www.perlego.com/book/1809940/logging-and-log-management-the-authoritative-guide-to-understanding-the-concepts-surrounding-logging-and-log-management-pdf
2. Design and Implementation of a Hybrid Ontological-Relational Data Repository for SIEM Systems
3. Advances and challenges in log analysis
4. Design and Analysis of a Dynamically Configured Log-based Distributed Security Event Detection Methodology
5. Advances in Security Information Management: Perceptions and Outcomes;Guillermo Suárez de Tangil,2013
Cited by
3 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献