[logs] Re: research on log analysis techniques

From: Jon Stearley (jrstear@private)
Date: Thu Aug 04 2005 - 10:00:33 PDT


> From: 345345@private
> Date: August 1, 2005 6:36:08 AM MDT
> To: loganalysis@private
> Subject: [logs] research on log analysis techniques
>
>
> Hello All,
>
> I am doing a research for my Bachelor Final Work and I would like to  
> ask
> you some things about log analysis.
> Basically, in this work I am writing, I am trying to find a way of  
> doing
> log analysis on a more efficient and safe basis:
> - Efficient: trying to shorten the time sysadmins put (or should put)  
> on
> log analysing, i.e.  I am trying to use some techniques from other
> fields of knowledge, e.g. artificial intelligence, for helping improve
> the process of log analysis.
> - Safe: using this techniques cannot hide any security relevant events
> of create any side effect for using those techniques.
>
> I ask you: Is someone doing something similar? If so, would you point  
> me
> some links of describe the ideas from your projects?

http://www.cs.sandia.gov/sisyphus/
http://kodu.neti.ee/~risto/loghound/
http://researchweb.watson.ibm.com/journal/sj/413/hellerstein.html
http://www.cs.berkeley.edu/~bodikp/
http://www.acm.org/sigs/sigkdd/kdd2005/papers-industry.html (full #4)
http://www.usenix.org/publications/library/proceedings/lisa98/ 
girardin.html
http://www.usenix.org/publications/library/proceedings/sec98/lee.html
http://www.usenix.org/publications/library/proceedings/lisa02/tech/ 
takada.html
http://www.vogue.is.uec.ac.jp/~koike/tudumi/tudumi.html

-- 
+--------------------------------------------------------------+
| Jon Stearley                  (505) 845-7571  (FAX 844-9297) |
| Sandia National Laboratories  Scalable Systems Integration   |
+--------------------------------------------------------------+


_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Thu Aug 04 2005 - 12:52:40 PDT