Smart Log Data Analytics (Record no. 361449)

MARC details
000 -CABECERA
campo de control de longitud fija 07245nam a22004095i 4500
001 - NÚMERO DE CONTROL
campo de control 361449
003 - IDENTIFICADOR DEL NÚMERO DE CONTROL
campo de control ES-MaUEC
005 - FECHA Y HORA DE LA ÚLTIMA TRANSACCIÓN
campo de control 20230102121400.0
006 - CÓDIGOS DE INFORMACIÓN DE LONGITUD FIJA--CARACTERÍSTICAS DEL MATERIAL ADICIONAL
campo de control de longitud fija a||||fo|||| 00| 0
007 - CAMPO FIJO DE DESCRIPCIÓN FÍSICA--INFORMACIÓN GENERAL
campo de control de longitud fija cr nn nnnaamaa
008 - DATOS DE LONGITUD FIJA--INFORMACIÓN GENERAL
campo de control de longitud fija 210828s2021 sz | s |||| 0|eng d
020 ## - NÚMERO INTERNACIONAL ESTÁNDAR DEL LIBRO
Número Internacional Estándar del Libro 9783030744502
024 7# - IDENTIFICADOR DE OTROS ESTÁNDARES
Número estándar o código 10.1007/978-3-030-74450-2
Fuente del número o código doi
040 ## - FUENTE DE LA CATALOGACIÓN
Centro catalogador/agencia de origen ES-MaUEC
Lengua de catalogación spa
Centro/agencia transcriptor ES-MaUEC
Centro/agencia modificador ES-MaUEC
050 #4 - SIGNATURA TOPOGRÁFICA DE LA BIBLIOTECA DEL CONGRESO
Número de clasificación QA76.9.A25
Número de documento/Ítem 2021 EB
100 1# - ENTRADA PRINCIPAL--NOMBRE DE PERSONA
Nombre de persona Skopik, Florian
Término indicativo de función/relación autor
9 (RLIN) 681258
245 10 - MENCIÓN DE TÍTULO
Título Smart Log Data Analytics
Resto del título Techniques for Advanced Security Analysis
Mención de responsabilidad, etc. by Florian Skopik, Markus Wurzenberger, Max Landauer.
250 ## - MENCIÓN DE EDICIÓN
Mención de edición First edition 2021
264 #1 - PRODUCCIÓN, PUBLICACIÓN, DISTRIBUCIÓN, FABRICACIÓN Y COPYRIGHT
Producción, publicación, distribución, fabricación y copyright Cham
Nombre del de productor, editor, distribuidor, fabricante Springer International Publising
Fecha de producción, publicación, distribución, fabricación o copyright 2021
300 ## - DESCRIPCIÓN FÍSICA
Extensión 1 recurso en línea (XV, 208 páginas)
Otras características físicas 65 ilustraciones, 36 ilustraciones a color
336 ## - TIPO DE CONTENIDO
Fuente rdacontent
Término de tipo de contenido Texto
Código de tipo de contenido txt
337 ## - TIPO DE MEDIO
Fuente rdamedia
Nombre/término del tipo de medio electrónico
Código del tipo de medio c
338 ## - TIPO DE SOPORTE
Fuente rdacarrier
Nombre/término del tipo de soporte recurso electrónico
Código del tipo de soporte cr
347 ## - CARACTERÍSTICAS DEL ARCHIVO DIGITAL
Tipo de archivo archivo de texto
Formato de codificación PDF
490 0# - MENCIÓN DE SERIE
Mención de serie Computer Science (SpringerNature-11645)
490 0# - MENCIÓN DE SERIE
Mención de serie Computer Science (R0) (SpringerNature-43710)
505 0# - NOTA DE CONTENIDO CON FORMATO
Nota de contenido con formato I1 -- Introduction -- 1.1 State of the art in security monitoring and anomaly detection -- 1.2 Current trends -- 1.3. future challenges -- 1.4 Log data analysis: today and tomorrow -- 1.5 Smart log data analytics: Structure of the book -- 1.6 Try it out: Hands-on examples throughout the book -- 2 Survey on log clustering approaches -- 2.1 Introduction. 2.2 Survey background -- 2.1 The nature of log data. 2.2 Static clustering -- 2.3 Dynamic clustering -- 2.4 Applications in the security domain -- 2.3 Survey method -- 2.3.1 Set of criteria -- 2.3.2 Literature search -- 2.4 Survey results -- 2.4.1 Purpose and applicability (P) -- 2.4.2 Clustering techniques (C) -- 2.4.3 Anomaly detection (AD) -- 2.4.4 Evaluation (E). 2.4.5 Discussion -- 2.5 Conclusion -- 3 Incremental log data clustering for processing large amounts of data online -- 3.1 Introduction -- 3.2 Concept for incremental clustering -- 3.2.1 Incremental clustering -- 3.2.2 Description of model -- 3.2.3 String metrics -- 3.2.4 Description of model M1.‑‑ 3.2.5 Time series analysis -- 3.3 Outlook and further development -- 3.4 Try it out -- 3.4.1 Exim Mainlog -- 3.4.2 Messages log file -- 4 Generating character-based templates for log data -- 4.1 Introduction -- 4.2 Concept for generating character-based templates -- 4.3 Cluster template generator algorithms4.3.1 Initial matching -- 4.3.2 Merge algorithm.-4.3.3 Length algorithm -- 4.3.4 Equalmerge algorithm -- 4.3.5 Token_char algorithm -- 4.3.6 Comparison -- 4.4 Outlook and further development -- 4.5 Try it out -- 4.5.1 Exim Mainlog -- 5 Time series analysis for temporal anomaly detection5.1 Introduction -- 5.2 Concept for dynamic clustering and AD -- 5.3 Cluster evolution -- 5.3.1 Clustering model -- 5.3.2 Tracking -- 5.3.3 Transitions -- 5.3.4 Evolution metrics -- 5.4 Time series analysis -- 5.4.1 Model -- 5.4.2 Forecast -- 5.4.3 Correlation -- 5.4.4 Detection -- 5.5 Example -- 5.5.1 Long-term analysis of Suricata logs -- 5.5.2 Short-term analysis of Audit logs -- 6 AECID: A light-weight log analysis approach for online anomaly detection -- 6.1 Introduction -- 6.2 The AECID approach -- 6.2.1 AMiner -- 6.2. AECID central -- 6.2. Detecting anomalies -- 6.2. Rule generator -- 6.2. Correlation engine -- 6.2. Detectable anomalies -- 6. System deployment and operation -- 6. Application scenarios -- 6. Try it out -- 6.5.1 Configuration of the AMiner for AIT-LDSv1. - 6.5.2 Apache Access logs -- 6.5.3 Exim Mainlog file -- 6.5.4 Audit logs -- 7. A concept for a tree-based log parser generator -- 7.1 Introduction -- 7.2 Tree-based parser concept -- 7.3 AECID-PG: tree-based log parser generator -- 7.3.1 Challenges when generating tree-like parsers -- 7.3.2 AECID-PG concept -- 7.3.3 AECID-PG rules -- 7.3.4 Features -- 7.4 Outlook and further application -- 7.5 Try it out -- 7.5.1 Exim Mainlog -- 7.5.2 Audit logs -- 8 Variable type detector for statistical analysis of log tokens -- 8.1 Introduction.-.-8.2 Variable type detector concept -- 8.3 Variable type detector algorithm -- 8.3.1 Sanitize log data -- 8.3.2 Initialize types -- 8.3.3 Update types -- 8.3.4 Compute indicators -- 8.3.5 Select tokens -- 8.3.6 Compute indicator weights -- 8.3.7 Report anomalies -- 8.4 Try it out -- 8.4.1 Apache Access log -- 9. Final remarks.
520 3# - SUMARIO, ETC.
Sumario, etc. This book provides insights into smart ways of computer log data analysis, with the goal of spotting adversarial actions. It is organized into 3 major parts with a total of 8 chapters that include a detailed view on existing solutions, as well as novel machine learning techniques that go far beyond state of the art. The first part of this book motivates the entire topic and highlights major challenges, trends and design criteria for log data analysis approaches, and further surveys and compares the state of the art. The second part of this book introduces concepts that apply character-based, rather than token-based, approaches and thus work on a more fine-grained level. Furthermore, these solutions were designed for "online use", not only forensic analysis, but also process new log lines as they arrive in an efficient single pass manner. An advanced method for time series analysis aims at detecting changes in the overall behavior profile of an observed system and spotting trends and periodicities through log analysis. The third part of this book introduces the design of the AMiner, which is an advanced open source component for log data anomaly mining. The AMiner comes with several detectors to spot new events, new parameters, new correlations, new values and unknown value combinations and can run as stand-alone solution or as sensor with connection to a SIEM solution. More advanced detectors help to determine the characteristics of variable parts of log lines, specifically the properties of numerical and categorical fields. Detailed examples throughout this book allow the reader to better understand and apply the introduced techniques with open source software. Step-by-step instructions help to get familiar with the concepts and to better comprehend their inner mechanisms. A log test data set is available as free download and enables the reader to get the system up and running in no time. This book is designed for researchers working in the field of cyber security, and specifically system monitoring, anomaly detection and intrusion detection. The content of this book will be particularly useful for advanced-level students studying computer science, computer technology, and information systems. Forward-thinking practitioners, who would benefit from becoming familiar with the advanced anomaly detection methods, will also be interested in this book.
988 ## - NOTA LOCAL 598
Nota local 598 (boletines) Springer_Computer_2021
650 #7 - PUNTO DE ACCESO ADICIONAL DE MATERIA--TÉRMINO DE MATERIA
Fuente del encabezamiento o término embne
9 (RLIN) 162648
Término de materia o nombre geográfico como elemento de entrada Data mining
650 #7 - PUNTO DE ACCESO ADICIONAL DE MATERIA--TÉRMINO DE MATERIA
Fuente del encabezamiento o término embne
Término de materia o nombre geográfico como elemento de entrada Seguridad informática
9 (RLIN) 158200
700 1# - PUNTO DE ACCESO ADICIONAL--NOMBRE DE PERSONA
Nombre de persona Wurzenberger, Markus
Término indicativo de función/relación autor
700 1# - PUNTO DE ACCESO ADICIONAL--NOMBRE DE PERSONA
Nombre de persona Landauer, Max
Término indicativo de función/relación autor
856 40 - LOCALIZACIÓN Y ACCESO ELECTRÓNICOS
Identificador Uniforme del Recurso https://go.openathens.net/redirector/universidadeuropea.es?url=https://doi.org/10.1007/978-3-030-74450-2
Nota pública Acceso a este recurso digital (usuarios Universidad Europea de Madrid)
999 ## - NÚMEROS DE CONTROL DE SISTEMA (KOHA)
-- 1
942 ## - ELEMENTOS DE PUNTO DE ACCESO ADICIONAL (KOHA)
Fuente del sistema de clasificación o colocación Library of Congress Classification
Tipo de ítem Koha LIBRO-E NO PRÉSTAMO
998 ## - DATOS ESTADÍSTICOS
Fecha de catalogación 01/2022
Tipo de materia E-book
Catalogador Sara Morillo
Catalogado
Holdings
Información adicional para el OPAC Código 2 (categoría) Estado de pérdida Fuente del sistema de clasificación o colocación Tipo de material Código 1: Estado físico No se presta Código de colección Estado Localización permanente Ubicación/localización actual Ubicación en estantería Fecha de adquisición Tipo de préstamo Total de préstamos Signatura topográfica completa Código de barras Fecha visto por última vez Precio válido a partir de Tipo de ítem Koha
Acceso concurrente No retirado   Library of Congress Classification E-Libro Buen estado Acceso electrónico Ciencias e Ingeniería Acceso electrónico Madrid Digital Madrid Digital Acceso Electrónico (UEM) 21/12/2021 En línea   QA76.9 .D3385 2021 EB eBook.19122090 22/12/2021 22/12/2021 LIBRO-E NO PRÉSTAMO