Data Mining Approach to Analysis of Computer Logs Using New Patterns

  • Authors:
  • Krzysztof Cabaj

  • Affiliations:
  • Institute of Computer Science, Warsaw University of Technology, Nowowiejska 15/19, 00-665 Warsaw, Poland, e-mail: kcabaj@elka.pw.edu.pl

  • Venue:
  • Proceedings of the 2008 conference on New Trends in Multimedia and Network Information Systems
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Due to the huge amount of currently collected data, only computer methods are able to analyze it. Data Mining techniques could be used for this purpose, but most of currently used techniques discovering global patterns loose information about local changes. In this paper the new patterns are proposed: frequent events and groups of events in data stream. They have two advantages: information about local changes in distribution of patterns is obtained and the number of discovered patterns is smaller than in other methods. Described experiments prove that patterns give valuable knowledge, for example, in analysis of computer logs. Analysis of firewall logs reveals interest of user, its favourite web pages and used portals. By using described methods for analysis of HoneyPot logs, detailed knowledge about malicious code and time of its activity could be received. Additionally, information about infected machines IP addresses and authentication data is automatically discovered.