Linux环境下的日志分析系统LASL
A Log Analyzing System for Linux LASL
-
摘要: 日志文件是计算机系统运行轨迹的写照,是入侵检测分析中重要的数据来源.日志分析主要用于入侵事件后采取相应的应急响应措施,最大可能地减少入侵造成的损失.LASL把传统的日志分析技术和移动Agent技术相结合,实现了Linux环境下的主机日志分析系统,具有智能化、自动化和分布式的特点.Abstract: As a data source, log files recorded the basic contents of intrusion detection system. The most popular and effective way to perform host-based intrusion detection is to audit log data and take some effective measures to decrease the loss. Integrating original log analyzing technique with mobile-agent, LASL implements a host-based log analyzing system. Compared with other log analyzing tools, LASL has intellectualized, automatic and distributed characters.