<div class="csl-bib-body">
<div class="csl-entry">Kurniawan, K., Ekelhart, A., Kiesling, E., Winkler, D., Quirchmayr, G., & Tjoa, A. M. (2022). VloGraph: A Virtual Knowledge Graph Framework for Distributed Security Log Analysis. <i>Machine Learning and Knowledge Extraction</i>, <i>4</i>(2), 371–396. https://doi.org/10.3390/make4020016</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/144335
-
dc.description.abstract
The integration of heterogeneous and weakly linked log data poses a major challenge in many log-analytic applications. Knowledge graphs (KGs) can facilitate such integration by providing a versatile representation that can interlink objects of interest and enrich log events with background knowledge. Furthermore, graph-pattern based query languages, such as SPARQL, can support rich log analyses by leveraging semantic relationships between objects in heterogeneous log streams. Constructing, materializing, and maintaining centralized log knowledge graphs, however, poses significant challenges. To tackle this issue, we propose VloGraph—a distributed and virtualized alternative to centralized log knowledge graph construction. The proposed approach does not involve any a priori parsing, aggregation, and processing of log data, but dynamically constructs a virtual log KG from heterogeneous raw log sources across multiple hosts. To explore the feasibility of this approach, we developed a prototype and demonstrate its applicability to three scenarios. Furthermore, we evaluate the approach in various experimental settings with multiple heterogeneous log sources and machines; the encouraging results from this evaluation suggest that the approach can enable efficient graph-based ad-hoc log analyses in federated settings.
en
dc.description.sponsorship
CDG Christian Doppler Forschungsgesellschaft; CDG Christian Doppler Forschungsgesellschaft
-
dc.language.iso
en
-
dc.publisher
MDPI
-
dc.relation.ispartof
Machine Learning and Knowledge Extraction
-
dc.rights.uri
http://creativecommons.org/licenses/by/4.0/
-
dc.subject
semantic log analysis
en
dc.subject
virtual log graphs
en
dc.subject
dynamic log extraction
en
dc.subject
decentralized logquerying
en
dc.subject
forensics
en
dc.title
VloGraph: A Virtual Knowledge Graph Framework for Distributed Security Log Analysis
en
dc.type
Article
en
dc.type
Artikel
de
dc.rights.license
Creative Commons Namensnennung 4.0 International
de
dc.rights.license
Creative Commons Attribution 4.0 International
en
dc.contributor.affiliation
Vienna University of Economics and Business, Austria
-
dc.contributor.affiliation
University of Vienna, Austria
-
dc.contributor.affiliation
Vienna University of Economics and Business, Austria