System and method for parsing, summarizing and reporting log data

作者: Thomas Hunt Schabo Grabowski , Jason Michael DeStefano

DOI:

关键词:

摘要: A system and method is disclosed which enables network administrators the like to quickly analyze data produced by log-producing devices such as firewalls routers. Unlike systems of prior art, herein automatically parses summarizes log before inserting it into one or more databases. This greatly reduces volume stored in database permits queries be run reports generated while many types attempted breaches security are still progress. Database maintenance may also accomplished delete archive old data.

参考文章(45)
Şükran Asarcıklı, Firewall monitoring using intrusion detection systems İzmir Institute of Technology. ,(2005)
Scott Matsumoto, Robert Adams, Diane Downie, Transactional monitoring system and method ,(2001)
Timothy David McCreery, Mahboud Zabetian, Apparatus and method of analyzing internet activity ,(1996)
Andrew Ginter, Kegan Kawano, Brad McMillan, Tom Hutchinson, Andy G. Mah, Adam Muegge, Rui Manuel Martins Lopes, Erik P. Hope, Brett Jensen, Method and computer program product for monitoring an industrial network ,(2004)
Andrew P. Sherman, Scott E. McCargar, Method for deallocating a log in database systems ,(1996)
Bryan Douglas Williams, Timothy P. Farley, Philip Charles Brass, Derek John Mezack, George C. Young, John M. Hammer, Method and System for Managing Computer Security Information ,(2001)