Log File Analysis with Context-Free GrammarsReport as inadecuate

Log File Analysis with Context-Free Grammars - Download this document for free, or read online. Document in PDF available to download.

1 University of Pretoria South Africa

Abstract : Classical intrusion analysis of network log files uses statistical machine learning or regular expressions. Where statistically machine learning methods are not analytically exact, methods based on regular expressions do not reach up very far in Chomsky’s hierarchy of languages. This paper focuses on parsing traces of network traffic using context-free grammars. -Green grammars- are used to describe acceptable log files while -red grammars- are used to represent known intrusion patterns. This technique can complement or augment existing approaches by providing additional precision. Analytically, the technique is also more powerful than existing techniques that use regular expressions.

Keywords : Intrusion detection log file analysis context-free grammars

Author: Gregory Bosman - Stefan Gruner -

Source: https://hal.archives-ouvertes.fr/


Related documents