SEC - a lightweight event correlation tool

Event correlation has become one of the most important techniques in today's network management, and there is a clear trend to extend its use to other application domains as well. Unfortunately, existing event correlation systems are often platform-dependent and heavyweight solutions that have complicated design, being therefore difficult to deploy and maintain, and requiring extensive user training. Their complexity and size makes them often unfeasible to apply for smaller networks and for smaller event correlation tasks. Also, some systems are cumbersome to use outside the domain of network fault management. In addition, commercial event correlation products tend to be quite expensive. In this paper the author presents a lightweight, open-source, and platform independent tool for rule-based event correlation called SEC (simple event correlator), and describes its application experience.

[1]  Stephen E. Hansen,et al.  Automated System Monitoring and Notification with Swatch , 1993, LISA.

[2]  Mark Weissman,et al.  Real-time telecommunication network management: extending event correlation with temporal constraints , 1995, Integrated Network Management.

[3]  Karl N. Levitt,et al.  GrIDS A Graph-Based Intrusion Detection System for Large Networks , 1996 .

[4]  Martin Roesch,et al.  Snort - Lightweight Intrusion Detection for Networks , 1999 .

[5]  Mark Weissman,et al.  GRACE: building next generation event correlation services , 2000, NOMS 2000. 2000 IEEE/IFIP Network Operations and Management Symposium 'The Networked Planet: Management Beyond 2000' (Cat. No.00CB37074).

[6]  Leonid Furman,et al.  Network Management : Open Source Solutions to Proprietary Problems , 2000 .

[7]  Carl Erickson,et al.  Extending UNIX System Logging with SHARP , 2000, LISA.

[8]  Simon Cozens,et al.  Professional Perl Programming , 2001 .

[9]  Stuart Staniford-Chen,et al.  Practical Automated Detection of Stealthy Portscans , 2002, J. Comput. Secur..

[10]  Risto Vaarandi Platform independent event correlation tool for network management , 2002, NOMS 2002. IEEE/IFIP Network Operations and Management Symposium. ' Management Solutions for the New Communications World'(Cat. No.02CH37327).