• DocumentCode
    3034130
  • Title

    The design and implement of the centralized log gathering and analysis system

  • Author

    Huang, Jian-hua ; Zhang, Man-qi ; Jiang, Yuan-long

  • Author_Institution
    Sch. of Inf. Sci. & Eng., East China Univ. of Sci. & Technol., Shanghai, China
  • Volume
    2
  • fYear
    2012
  • fDate
    25-27 May 2012
  • Firstpage
    268
  • Lastpage
    273
  • Abstract
    Logs generated by network devices and systems provide important information for network management. In this paper, we describe a centralized syslog system which gathers and analyzes log messages from a number of routers, switches and firewalls. The gathered logs are filtered and categorized with regular expression, and finally stored in a MySQL database with format. Through the statistics analysis, feature-based detection on security events, the system can effectively find out abnormal behavior of network devices and ensure the network security. Some methods are found out to allow us to check if the network behavior is unusual. These perspective methods also provide the basis of network management and security strategy design for administrators, thereby strengthen further network management.
  • Keywords
    firewall; regular expression; router; syslog;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Automation Engineering (CSAE), 2012 IEEE International Conference on
  • Conference_Location
    Zhangjiajie, China
  • Print_ISBN
    978-1-4673-0088-9
  • Type

    conf

  • DOI
    10.1109/CSAE.2012.6272772
  • Filename
    6272772