DocumentCode :
2448659
Title :
Pattern and Policy Driven Log Analysis for Software Monitoring
Author :
Razavi, Ali ; Kontogiannis, Kostas
Author_Institution :
Dept. of Electr. & Comput. Eng., Unversity of Waterloo, Waterloo, ON
fYear :
2008
fDate :
July 28 2008-Aug. 1 2008
Firstpage :
108
Lastpage :
111
Abstract :
The component-based nature of large industrial software systems that consist of a number of diverse collaborating applications, pose significant challenges with respect to system maintenance, monitoring, auditing, and diagnosing. In this context, a monitoring and diagnostic system interprets log data to recognize patterns of significant events that conform to specific threat models. Threat models have been used by the software industry for analyzing and documenting a systempsilas risks in order to understand a systempsilas threat profile. In this paper, we propose a framework whereby patterns of significant events are represented as expressions of a specialized monitoring language that are used to annotate specific threat models. An approximate matching technique that is based on the Viterbi algorithm is then used to identify whether system generated events, fit the given patterns. The technique has been applied and evaluated considering threat models and monitoring policies in logs that have been obtained from multi-user MS-Windows based systems.
Keywords :
object-oriented programming; program diagnostics; risk analysis; security of data; Viterbi algorithm; component-based software; industrial software systems; pattern driven log analysis; pattern recognition; policy driven log analysis; software monitoring; system auditing; system diagnosis; system maintenance; system monitoring; system risk; system threat profile; Application software; Collaborative software; Computer industry; Context modeling; Monitoring; Pattern analysis; Pattern matching; Pattern recognition; Risk analysis; Software systems; Software Auditing; Software Monitoring; Trace Analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications, 2008. COMPSAC '08. 32nd Annual IEEE International
Conference_Location :
Turku
ISSN :
0730-3157
Print_ISBN :
978-0-7695-3262-2
Electronic_ISBN :
0730-3157
Type :
conf
DOI :
10.1109/COMPSAC.2008.81
Filename :
4591541
Link To Document :
بازگشت