Application of Data Mining in ESMC

余少华,关勇,戴一奇
DOI: https://doi.org/10.3969/j.issn.1000-3428.2003.19.036
2003-01-01
Abstract:The article presents the architecture of enterprise security management center (ESMC) based on log mining which is distributed and supports multi-protocol. It can collect, normalize and aggregate the massive and various log information, generate the consolidating notifications, analyze the notifications by the checking model to find the potential compromises and attacks in the system, take real-time response actions. Finally, the paper describes how to build the checking model by data mining.
What problem does this paper attempt to address?