Anomaly Detection for Network Connection Logs

12/01/2018
by   Swapneel Mehta, et al.
0

We leverage a streaming architecture based on ELK, Spark and Hadoop in order to collect, store, and analyse database connection logs in near real-time. The proposed system investigates outliers using unsupervised learning; widely adopted clustering and classification algorithms for log data, highlighting the subtle variances in each model by visualisation of outliers. Arriving at a novel solution to evaluate untagged, unfiltered connection logs, we propose an approach that can be extrapolated to a generalised system of analysing connection logs across a large infrastructure comprising thousands of individual nodes and generating hundreds of lines in logs per second.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/25/2022

Topological Data Analysis for Anomaly Detection in Host-Based Logs

Topological Data Analysis (TDA) gives practioners the ability to analyse...
research
12/01/2018

A Big Data Architecture for Log Data Storage and Analysis

We propose an architecture for analysing database connection logs across...
research
02/08/2019

BINet: Multi-perspective Business Process Anomaly Classification

In this paper, we introduce BINet, a neural network architecture for rea...
research
05/21/2023

Anomaly Detection Using One-Class SVM for Logs of Juniper Router Devices

The article deals with anomaly detection of Juniper router logs. Abnorma...
research
06/01/2022

Mining Function Homology of Bot Loaders from Honeypot Logs

Self-contained loaders are widely adopted in botnets for injecting loadi...
research
01/24/2019

Mokka: RSM for open networks

Mokka is a PC (CAP theorem) consensus algorithm for handling replicated ...
research
10/11/2022

Digitization of Raster Logs: A Deep Learning Approach

Raster well-log images are digital representations of well-logs data gen...

Please sign up or login with your details

Forgot password? Click here to reset