Title :
The design and implement of the centralized log gathering and analysis system
Author :
Huang, Jian-hua ; Zhang, Man-qi ; Jiang, Yuan-long
Author_Institution :
Sch. of Inf. Sci. & Eng., East China Univ. of Sci. & Technol., Shanghai, China
Abstract :
Logs generated by network devices and systems provide important information for network management. In this paper, we describe a centralized syslog system which gathers and analyzes log messages from a number of routers, switches and firewalls. The gathered logs are filtered and categorized with regular expression, and finally stored in a MySQL database with format. Through the statistics analysis, feature-based detection on security events, the system can effectively find out abnormal behavior of network devices and ensure the network security. Some methods are found out to allow us to check if the network behavior is unusual. These perspective methods also provide the basis of network management and security strategy design for administrators, thereby strengthen further network management.
Keywords :
firewall; regular expression; router; syslog;
Conference_Titel :
Computer Science and Automation Engineering (CSAE), 2012 IEEE International Conference on
Conference_Location :
Zhangjiajie, China
Print_ISBN :
978-1-4673-0088-9
DOI :
10.1109/CSAE.2012.6272772