Log File Analysis with Context-Free Grammars

dc.contributor.authorGruner, Stefan
dc.contributor.upauthorBosman, Gregory
dc.date.accessioned2014-02-03T12:09:32Z
dc.date.available2014-02-03T12:09:32Z
dc.date.created2012
dc.date.issued2013
dc.description.abstractClassical ways of intrusion analysis from textual communication log files are either AI-based (such as by combinations of data mining with various techniques of machine learning), or they are based on regular expressions (such as the scanners implemented in the CISCO boxes). Whereas AI-based heuristics are not analytically exact, methods based on regular expressions do not reach very far in Chomsky's hierarchy of languages. In this short chapter we describe work in progress on the topic of parsing traces of network traffic with context-free grammars. "Green" grammars describe acceptable log files, whereas "red" grammars represent already known specific patterns of intrusion attempts. This technique can complement or augment the aready existing AI-approaches with additional precision. Analytically it is also more powerful than CISCO's technique on the basis of regular expressions.en_US
dc.description.librarianmv2014en_US
dc.description.urihttp://link.springer.com/chapter/10.1007/978-3-642-41148-9_10en_US
dc.format.extent9 p.en_US
dc.format.mediumPDFen_US
dc.identifier.citationGregory Bosman & Stefan Gruner: Log File Analysis with Context-Free Grammars. Advances in Digital Forensics IX, Chapter 10, pp. 145-152, IFIP Advances in Information and Communication Technology 410, Springer-Verlag, 2013.en_US
dc.identifier.isbn978-3-642-41147-2
dc.identifier.urihttp://hdl.handle.net/2263/33235
dc.language.isoenen_US
dc.publisherSpringer-Verlagen_US
dc.relation.ispartofseriesIFIP Advances in Information and Communication Technology 410en_US
dc.rightsSpringer-Verlag holds the copyright of the finally published version of this Pre-Print. The copyright of this Pre-Print itself, as provided by this "UPSpace" repository, is with the authors.en_US
dc.subjectIntrusion detectionen_US
dc.subjectLog file analysisen_US
dc.subjectContext-free grammarsen_US
dc.subjectDecision problemen_US
dc.titleLog File Analysis with Context-Free Grammarsen_US
dc.typeBook chapteren_US
dc.typePreprint Articleen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Bosman_Log_2014.pdf
Size:
100.83 KB
Format:
Adobe Portable Document Format
Description:
Preprint

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: