Generation of rational expressions starting from journalized events
> Description The analyse of log is one of the better means to supervise the correct operation of a system or to carry out intrusion detection. For that, the rational expressions are a very powerful tool in order to describe the events. The generation of these expressions can be a long work, especially in an initial way when administrator receive an hundreds event per day. Slct is a tool allowing to guide administrator by presenting solutions to him describing the greatest possible event number.  
> Context & Dates Talk made during RÉSIST, on 30 August 2004.
> Author Denis Ducamp  
Table of content
Plan (1/6) : la journalisation
La journalisation
La journalisation : l'analyse de journaux
Plan (2/6) : la détection d'intrusion
La détection d'intrusion
La détection d'intrusion
Plan (3/6) : les expressions rationnelles
Les expressions rationnelles
Plan (4/6) : slct
slct : fonctionnement
slct : exemples (1/3)
slct : exemples (2/3)
slct : exemples (3/3)
Plan (5/6) : des utilisations de ces expressions
Des utilisations de ces expressions : scripts maison
Des utilisations... pour l'affichage temps réel
Des utilisations... en mode statique : swatch
Des utilisations... en mode statique : logcheck
Des utilisations... en mode dynamique : logsurfer
Des utilisations... en mode dynamique : sec
Plan (6/6) : d'autres possibilités
D'autres possibilités
> Related documents
[Presentation]  Logging and incident processing [15 May 2008 - French]
[Presentation]  Workstation Security [29 March 2007 - French]
[Presentation]  Logs and incident processing [29 March 2007 - French]
[Presentation]  Generation of regular expressions from logged events [2 February 2005 - French]
[Presentation]  Useful standards for network security [20 October 2003 - French]
[Presentation]  Logging (how to be ready to incidents) [6 February 2003 - French]
[Presentation]  Internet Firewall Management [23 June 2002 - French]
[Tip]  Installing Syslog-NG [29 October 2001 - French]
[Presentation]  XML-Logs: Analyse your logs using XML encoding [10 October 2000 - French]
[Tool]  xml-logs tool [Log management using XML - English]
[Standard]  Universal Format for Logger Messages [May 1999 - English]
> Copyright © 2004, Hervé Schauer Consultants, all rights reserved.


