Multilayer Block Models for Exploratory Analysis of Computer Event Logs

06/21/2022
by   Corentin Larroche, et al.
0

We investigate a graph-based approach to exploratory data analysis in the context of network security monitoring. Given a possibly large batch of event logs describing ongoing activity, we first represent these events as a bipartite multiplex graph. We then apply a model-based biclustering algorithm to extract relevant clusters of entities and interactions between these clusters, thereby providing a simplified situational picture. We illustrate this methodology through two case studies addressing network flow records and authentication logs, respectively. In both cases, the inferred clusters reveal the functional roles of entities as well as relevant behavioral patterns. Displaying interactions between these clusters also helps uncover malicious activity. Our code is available at https://github.com/cl-anssi/MultilayerBlockModels.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/16/2018

Analytic Provenance Datasets: A Data Repository of Human Analysis Activity and Interaction Logs

We present an analytic provenance data repository that can be used to st...
research
10/18/2022

EventGraph at CASE 2021 Task 1: A General Graph-based Approach to Protest Event Extraction

This paper presents our submission to the 2022 edition of the CASE 2021 ...
research
05/31/2021

Document-level Event Extraction via Heterogeneous Graph-based Interaction Model with a Tracker

Document-level event extraction aims to recognize event information from...
research
09/03/2019

GrAALF:Supporting Graphical Analysis of Audit Logs for Forensics

System-call level audit logs often play a critical role in computer fore...
research
12/02/2022

Assessing Anonymized System Logs Usefulness for Behavioral Analysis in RNN Models

System logs are a common source of monitoring data for analyzing computi...
research
03/22/2021

Human-like Controllable Image Captioning with Verb-specific Semantic Roles

Controllable Image Captioning (CIC) – generating image descriptions foll...
research
05/10/2017

Mind the Gap: A Well Log Data Analysis

The main task in oil and gas exploration is to gain an understanding of ...

Please sign up or login with your details

Forgot password? Click here to reset