- Title
- Pseudo-random access compressed archive for security log data
- Creator
- Radley, Johannes Jurgens
- ThesisAdvisor
- Bradshaw, Karen
- ThesisAdvisor
- Irwin, Barry
- Subject
- Computer security
- Subject
- Information storage and retrieval systems
- Subject
- Data compression (Computer science)
- Date
- 2015
- Type
- Thesis
- Type
- Masters
- Type
- MSc
- Identifier
- vital:4723
- Identifier
- http://hdl.handle.net/10962/d1020019
- Description
- We are surrounded by an increasing number of devices and applications that produce a huge quantity of machine generated data. Almost all the machine data contains some element of security information that can be used to discover, monitor and investigate security events.The work proposes a pseudo-random access compressed storage method for log data to be used with an information retrieval system that in turn provides the ability to search and correlate log data and the corresponding events. We explain the method for converting log files into distinct events and storing the events in a compressed file. This yields an entry identifier for each log entry that provides a pointer that can be used by indexing methods. The research also evaluates the compression performance penalties encountered by using this storage system, including decreased compression ratio, as well as increased compression and decompression times.
- Format
- 99 p., pdf
- Publisher
- Rhodes University, Faculty of Science, Computer Science
- Language
- English
- Rights
- Radley, Johannes Jurgens
- Hits: 2285
- Visitors: 2411
- Downloads: 168
Thumbnail | File | Description | Size | Format | |||
---|---|---|---|---|---|---|---|
View Details | SOURCEPDF | 1 MB | Adobe Acrobat PDF | View Details |