• Complex
  • Title
  • Author
  • Keyword
  • Abstract
  • Scholars
Search

Author:

Qin, Tao (Qin, Tao.) | He, Chao (He, Chao.) | Jiang, Hezhi (Jiang, Hezhi.) | Chen, Ruoya (Chen, Ruoya.)

Indexed by:

CPCI-S

Abstract:

System log is one of the most important data sources for cloud security monitoring. But it is a difficult task to utilize the logs due to their various formats. In this paper, we proposed a model named Behavior Rhythm to characterize massive logs and achieve the goal of granular user behavior management and security monitoring. Firstly, we employ the logging IP address and time to construct the Behavior Rhythm, one point in the Behavior Rhythm corresponding to one logging behavior. Logging behaviors at different time of the same user are similar due to their habits and the points will centralize together in the Behavior Rhythm, thus the abnormal behaviors can be detected based on behavior point distribution. Secondly, we propose the concept of Operation and Maintenance Frequency (OMF) to capture the behavior characteristics of normal users, which is efficient in behavior profiling by combined logging time, logging IP address and number of input commands. Finally, we employ PrefixSpan to mine the frequent command sequences used by abnormal users. In turn, we can reconstruct the attack steps, and then design suitable defense policies based on detailed investigation of the attack characteristics. Experimental results based on massive log data collected from the campus network center of Xian Jiaotong University verify that the methods proposed in this paper are efficient in detailed behavior characteristics extraction and security monitoring, which can not only obtain the behavior profiles of normal users, but also extract the detailed commands used by specific attacks, the analysis results lay a solid foundation for cloud security management.

Keyword:

Author Community:

  • [ 1 ] [Qin, Tao; He, Chao; Jiang, Hezhi; Chen, Ruoya] Xi An Jiao Tong Univ, Xian 710049, Peoples R China

Reprint Author's Address:

  • Xi An Jiao Tong Univ, Xian 710049, Peoples R China.

Show more details

Related Keywords:

Related Article:

Source :

2018 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS)

ISSN: 2474-025X

Year: 2018

Language: English

Cited Count:

WoS CC Cited Count: 0

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 5

Affiliated Colleges:

FAQ| About| Online/Total:495/168719578
Address:XI'AN JIAOTONG UNIVERSITY LIBRARY(No.28, Xianning West Road, Xi'an, Shaanxi Post Code:710049) Contact Us:029-82667865
Copyright:XI'AN JIAOTONG UNIVERSITY LIBRARY Technical Support:Beijing Aegean Software Co., Ltd.