A Log-Based Mining System for Network Node Correlation

Yongzheng Zhang,Binxing Fang,Yue Chi,Xiaochun Yun
DOI: https://doi.org/10.1007/1-84628-352-3_17
2006-01-01
Abstract:In the field of network security, people become aware of the importance of study on the connectivity between network nodes. Based on analyzing the connectivity, this paper introduces a conception of network node correlation (NNC) and designs a novel log-based NNC mining system which adopts a typical distributed architecture based on agent. By means of bayesian network, this system can accurately and effectively mine high-level NNCs on application layer. The mined results can provide useful information for some security fields such as network risk assessment, vulnerability and intrusion detection, and virus propagation.
What problem does this paper attempt to address?