摘要
日志文件分析是系统安全检测的重要内容;同时日志文件也是计算机取证的重要依据。本文针对分布式网络日志文件管理和分析中安全性低、相关性分析弱的问题,提出了基于Syslog协议的日志文安全管理和分析模型(SISyslog),并提出了该模型的实现方法。
Log files analysis is the important contain of system security inspect, and log files is the primarily evidence of computer forensics. The paper aim at the two problems of low capability in security and relating analysis of how to manage and analyze distributing network's log files. Presented a management and analysis policy model of distributing network's log files base on Syslog protocol, and the method of how to realize the model is presented.
出处
《湖南科技学院学报》
2006年第5期164-167,共4页
Journal of Hunan University of Science and Engineering
基金
湖南省自然科学基金项目(03JJY3105)