arrow
Return

VloGraph: A Virtual Knowledge Graph Framework for Distributed Security Log Analysis

delete2022-04-11
delete3
delete
OA
AI
K
Kabul Kurniawan *
A
Andreas Ekelhart
E
Elmar Kiesling
D
Dietmar Winkler
G
Gerald Quirchmayr
A
A Min Tjoa
DOI:10.3390/make4020016delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The integration of heterogeneous and weakly linked log data poses a major challenge in many log-analytic applications. Knowledge graphs (KGs) can facilitate such integration by providing a versatile representation that can interlink objects of interest and enrich log events with background knowledge. Furthermore, graph-pattern based query languages, such as SPARQL, can support rich log analyses by leveraging semantic relationships between objects in heterogeneous log streams. Constructing, materializing, and maintaining centralized log knowledge graphs, however, poses significant challenges. To tackle this issue, we propose VloGraph-a distributed and virtualized alternative to centralized log knowledge graph construction. The proposed approach does not involve any a priori parsing, aggregation, and processing of log data, but dynamically constructs a virtual log KG from heterogeneous raw log sources across multiple hosts. To explore the feasibility of this approach, we developed a prototype and demonstrate its applicability to three scenarios. Furthermore, we evaluate the approach in various experimental settings with multiple heterogeneous log sources and machines; the encouraging results from this evaluation suggest that the approach can enable efficient graph-based ad-hoc log analyses in federated settings.
Keywords:
semantic log analysis
virtual log graphs
dynamic log extraction
decentralized logquerying
forensics

Journal

M
Machine Learning and Knowledge Extraction
IF:
6
Papers:
795
Citations:
1.8K

Organization

U
University of Vienna
Scholars:
1.7W
Papers: 1.6W
Citations: 40
V
vienna university of economics & business
Scholars:
1.1K
Papers: 1.4K
Citations: 2