Improving Anomaly Detection Event Analysis Using the EventRank Algorithm

  • Authors:
  • Kyrre Begnum;Mark Burgess

  • Affiliations:
  • Oslo University College, Norway;Oslo University College, Norway

  • Venue:
  • AIMS '07 Proceedings of the 1st international conference on Autonomous Infrastructure, Management and Security: Inter-Domain Management
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

We discuss an approach to reducing the number of events accepted by anomaly detection systems, based on alternative schemes for interest-ranking. The basic assumption is that regular and periodic usage of a system will yield patterns of events that can be learned by data-mining. Events that deviate from this pattern can then be filtered out and receive special attention. Our approach compares the anomaly detection framework from Cfengine and the EventRank algorithm for the analysis of the event logs. We show that the EventRank algorithm can be used to successfully prune periodic events from real-life data.