BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//conference.c3w.at//bsv19//KSJR9L
BEGIN:VTIMEZONE
TZID:Europe/Vienna
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsv19-E8GCJX@cfp.bsidesvienna.at
DTSTART;TZID=Europe/Vienna:20191130T140500
DTEND;TZID=Europe/Vienna:20191130T144500
DESCRIPTION:Existing signature-based intrusion detection systems are based 
 on manually-defined patterns that are known to correspond to particular at
 tacks and are therefore unable to disclose any previously unknown threats\
 , such as zero day exploits. ÆCID (Automatic Event Correlation for Incide
 nt Detection) alleviates this problem by employing self-learning anomaly d
 etection. ÆCID is capable of automatically learning the complex syntax of
  log files\, classify events\, and extract relevant parameters for advance
 d analysis. This includes the derivation of rules regarding the correlatio
 n of events as well as occurrences of parameter values. In addition\, ÆCI
 D carries out statistical analyses on the observed values and reports all 
 significant changes of system behavior to security analysts. ÆCID’s ope
 n-source log sensor\, the AMiner that enables efficient log parsing\, allo
 ws to build log analysis pipelines using a number of modules. The AMiner i
 s designed as a light-weight component that fits seamlessly into any syste
 m and has minimal requirements regarding processing power and required mem
 ory. Finally\, the AMiner in combination with ÆCID supports connection to
  existing security solutions\, such as SIEMs\, by providing interfaces to 
 standard message queue technologies\, such as Kafka. \n\nOur talk will con
 sist of two parts: First\, we will discuss some basic considerations when 
 it comes to log data analysis and outline our strategies of tackling the e
 ncompassed challenges\, including the parsing of logs from heterogeneous s
 ources and design of anomaly detection methods. Then\, we will present som
 e selected features of ÆCID in a practical demonstration.
DTSTAMP:20260908T060338Z
LOCATION:Dachsaal
SUMMARY:ÆCID: A self-learning Anomaly Detection Approach Based on Light-we
 ight Log Analytics - Max Landauer\, Markus Wurzenberger
URL:https://cfp.bsidesvienna.at/bsv19/talk/E8GCJX/
END:VEVENT
END:VCALENDAR
