[logs] Event Correlation for Analysis

From: Rainer Gerhards (rgerhardsat_private)
Date: Tue Mar 04 2003 - 09:16:48 PST

  • Next message: Jaswinder: "[logs] how to log cisco router activity"

    Hi all,
    
    I have today begun work on the description of event correlation
    algorithms. Right now, we are focussed on Windows, but I can see there
    are others to come - PIX is another prominent example.
    
    I am looking for prexisting work in this area - I would prefer not to
    re-invent the wheel...
    
    Here is a sample of what I intend to do:
    
    http://www.monitorware.com/Common/en/SecurityReference/Win-EventCorrelat
    ion-ProcessTracking.asp
    
    (again, one of my "lovely" long URLs - sorry for that. Make sure it ends
    in ".asp")
    
    I would welcome any comments and links to similar resources.
    
    Many thanks,
    Rainer
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Tue Mar 04 2003 - 09:23:57 PST