The ever-rising complexity of operating systems and communication networks has resulted in an increased difficulty in designing reliable security protection mechanisms. As a last line of defense, automated audit trail analysis can be used to detect various forms of security intrusions. However, automated audit trail analysis is difficult because of the high amount of audit data. This difficulty is even compounded in a distributed environment, where an attack evideence may span numerous hosts of possibly different architectures, operating systems and auditing facilities.
Click Here to download this article