• Title/Summary/Keyword: Event Correlation Analysis

Search Result 201, Processing Time 0.027 seconds

A Study on Event Log Correlation Analysis for Control System Threat Analysis (제어시스템 위협분석을 위한 Event Log 상관분석에 관한 연구)

  • Kim, Jongmin;Kim, Minsu;Lee, DongHwi
    • Convergence Security Journal
    • /
    • v.17 no.5
    • /
    • pp.35-40
    • /
    • 2017
  • The control system can have such threats as information leakage and falsification through various routes due to communications network fusion with public network. As the issues about security and the infringe cases by new attack methods are diversified recently, with the security system that makes information data database by simply blocking and checking it is difficult to cope with new types of threats. It is also difficult to respond security threats by insiders who have security access authority with the existing security equipment. To respond the threats by insiders, it is necessary to collect and analyze Event Log occurring in the internal system realtime. Therefore, this study could find out whether there is correlation of the elements among Event Logs through correlation analysis based on Event Logs that occur real time in the control system, and based on the analysis result, the study is expected to contribute to studies in this field.

A Study on the Measurement of Spatial Density and Structural Characteristic Evaluation using Discrete Event Simulation (이산사건 시뮬레이션을 활용한 공간밀도측정 및 구조특성평가)

  • Yoon, So Hee;Kim, Gun A;Kim, Suk Tae
    • Journal of Korea Multimedia Society
    • /
    • v.20 no.7
    • /
    • pp.1090-1101
    • /
    • 2017
  • This study analyzes spatial density and integration of Space Syntax and Discrete Event Simulation (DEVS) of complex system theory and analyzes spatial structure by property, type and depth. The aim of this study is to secure the validity of the theoretical application. The study evaluated the correlation between spatial density and integration by setting up eight types of analysis models. In addition, analyzed the correlation of structural characteristics and approached the application of discrete event simulation of spatial syntax theory. It is confirmed that the concept of integration of spatial syntax theory and analysis using discrete event simulation are valid as new spatial analysis methodology. Also expect that realistic and concrete predictions will be possible if discrete event simulation evolves into research for space allocation and space efficiency optimization.

Architecture Modeling and Performance Analysis of Event Rule Engine (이벤트 파싱 엔진의 구조 설계와 성능 분석)

  • 윤태웅;민덕기
    • Proceedings of the Korea Society for Simulation Conference
    • /
    • 2003.11a
    • /
    • pp.51-57
    • /
    • 2003
  • In operating distributed systems, proactive management is one of the major concerns for better quality of service and future capacity planning. In order to handle this management problem effectively, it is necessary to analyze performances of the distributed system and events generated by components in the system. This paper provides a rule-based event parsing engine for proactive management. Our event parsing engine uses object hooking-based and event-token approaches. The object hooking-based approach prepares new conditions and actions in Java classes and allows dynamically exchange them as hook objects in run time. The event-token approach allows the event parsing engine consider a proper sequence and relationship among events as an event token to trigger an action. We analyze the performance of our event parsing engine with two different implementations of rule structure; one is table-based and the other is tree-based.

  • PDF

An Evaluation Method for Tornado Missile Strike Probability with Stochastic Correlation

  • Eguchi, Yuzuru;Murakami, Takahiro;Hirakuchi, Hiromaru;Sugimoto, Soichiro;Hattori, Yasuo
    • Nuclear Engineering and Technology
    • /
    • v.49 no.2
    • /
    • pp.395-403
    • /
    • 2017
  • An efficient evaluation method for the probability of a tornado missile strike without using the Monte Carlo method is proposed in this paper. A major part of the proposed probability evaluation is based on numerical results computed using an in-house code, Tornado-borne missile analysis code, which enables us to evaluate the liftoff and flight behaviors of unconstrained objects on the ground driven by a tornado. Using the Tornado-borne missile analysis code, we can obtain a stochastic correlation between local wind speed and flight distance of each object, and this stochastic correlation is used to evaluate the conditional strike probability, $Q_V(r)$, of a missile located at position r, where the local wind speed is V. In contrast, the annual exceedance probability of local wind speed, which can be computed using a tornado hazard analysis code, is used to derive the probability density function, p(V). Then, we finally obtain the annual probability of tornado missile strike on a structure with the convolutional integration of product of $Q_V(r)$ and p(V) over V. The evaluation method is applied to a simple problem to qualitatively confirm the validity, and to quantitatively verify the results for two extreme cases in which an object is located just in the vicinity of or far away from the structure.

The Effect of Antecedent Moisture Conditions on the Contributions of Runoff Components to Stormflow in the Coniferous Forest Catchment

  • Choi, Hyung-Tae;Kim, Kyong-Ha;Lee, Choong-Hwa
    • Journal of Korean Society of Forest Science
    • /
    • v.99 no.5
    • /
    • pp.755-761
    • /
    • 2010
  • This study analyzed water quality data from a coniferous forest catchment in order to quantify the contributions of runoff components to stormflow, and to understand the effects of antecedent moisture conditions within catchment on the contributions of runoff components. Hydrograph separation by the twocomponent mixing model analysis was used to partition stormflow discharge into pre-event and event components for total 10 events in 2005 and 2008. To simplify the analysis, this study used single geochemical tracer with Na+. The result shows that the average contributions of event water and pre-event water were 34.8% and 65.2% of total stormflow of all 10 events, respectively. The event water contributions for each event varied from 18.8% to 47.9%. As the results of correlation analysis between event water contributions versus some storm event characteristics, 10 day antecedent rainfall and 1 day antecedent streamflow are significantly correlated with event water contributions. These results can provide insight which will contribute to understand the importance of antecedent moisture conditions in the generation of event water, and be used basic information to stormflow generation process in forest catchment.

Correlation Analysis of Event Logs for System Fault Detection (시스템 결함 분석을 위한 이벤트 로그 연관성에 관한 연구)

  • Park, Ju-Won;Kim, Eunhye;Yeom, Jaekeun;Kim, Sungho
    • Journal of Korean Society of Industrial and Systems Engineering
    • /
    • v.39 no.2
    • /
    • pp.129-137
    • /
    • 2016
  • To identify the cause of the error and maintain the health of system, an administrator usually analyzes event log data since it contains useful information to infer the cause of the error. However, because today's systems are huge and complex, it is almost impossible for administrators to manually analyze event log files to identify the cause of an error. In particular, as OpenStack, which is being widely used as cloud management system, operates with various service modules being linked to multiple servers, it is hard to access each node and analyze event log messages for each service module in the case of an error. For this, in this paper, we propose a novel message-based log analysis method that enables the administrator to find the cause of an error quickly. Specifically, the proposed method 1) consolidates event log data generated from system level and application service level, 2) clusters the consolidated data based on messages, and 3) analyzes interrelations among message groups in order to promptly identify the cause of a system error. This study has great significance in the following three aspects. First, the root cause of the error can be identified by collecting event logs of both system level and application service level and analyzing interrelations among the logs. Second, administrators do not need to classify messages for training since unsupervised learning of event log messages is applied. Third, using Dynamic Time Warping, an algorithm for measuring similarity of dynamic patterns over time increases accuracy of analysis on patterns generated from distributed system in which time synchronization is not exactly consistent.

Sensitivity analysis of failure correlation between structures, systems, and components on system risk

  • Seunghyun Eem ;Shinyoung Kwag ;In-Kil Choi ;Daegi Hahm
    • Nuclear Engineering and Technology
    • /
    • v.55 no.3
    • /
    • pp.981-988
    • /
    • 2023
  • A seismic event caused an accident at the Fukushima Nuclear Power Plant, which further resulted in simultaneous accidents at several units. Consequently, this incident has aroused great interest in the safety of nuclear power plants worldwide. A reasonable safety evaluation of such an external event should appropriately consider the correlation between SSCs (structures, systems, and components) and the probability of failure. However, a probabilistic safety assessment in current nuclear industries is performed conservatively, assuming that the failure correlation between SSCs is independent or completely dependent. This is an extreme assumption; a reasonable risk can be calculated, or risk-based decision-making can be conducted only when the appropriate failure correlation between SSCs is considered. Thus, this study analyzed the effect of the failure correlation of SSCs on the safety of the system to realize rational safety assessment and decision-making. Consequently, the impact on the system differs according to the size of the failure probability of the SSCs and the AND and OR conditions.

Analysis of bivariate recurrent event data with zero inflation

  • Kim, Taeun;Kim, Yang-Jin
    • Communications for Statistical Applications and Methods
    • /
    • v.27 no.1
    • /
    • pp.37-46
    • /
    • 2020
  • Recurrent event data frequently occur in clinical studies, demography, engineering reliability and so on (Cook and Lawless, The Statistical Analysis of Recurrent Events, Springer, 2007). Sometimes, two or more different but related type of recurrent events may occur simultaneously. In this study, our interest is to estimate the covariate effect on bivariate recurrent event times with zero inflations. Such zero inflation can be related with susceptibility. In the context of bivariate recurrent event data, furthermore, such susceptibilities may be different according to the type of event. We propose a joint model including both two intensity functions and two cure rate functions. Bivariate frailty effects are adopted to model the correlation between recurrent events. Parameter estimates are obtained by maximizing the likelihood derived under a piecewise constant hazard assumption. According to simulation results, the proposed method brings unbiased estimates while the model ignoring cure rate models gives underestimated covariate effects and overestimated variance estimates. We apply the proposed method to a set of bivariate recurrent infection data in a study of child patients with leukemia.

The Design of an Extended Complex Event Model based on Event Correlation using Aspect Oriented Programming

  • Kum, Deuk-Kyu
    • Journal of the Korea Society of Computer and Information
    • /
    • v.22 no.10
    • /
    • pp.109-119
    • /
    • 2017
  • In recent through development of IOT owing to that mass stream data is being generated in variety of application complex event processing technology is being watched with keen interest as a technology to analyze this kind of real-time continuous data. However, the existing study related with complex event processing only comes to an end at simple event processing based on low-level event or comes to an end at service defect discovery with providing limited operator and so on. Accordingly, there would be limitation to provide useful analysis information. In this paper in consideration of complex event along with aspect-oriented programming an extended complex event model is provided, which is possible to provide more valuable and useful information. Specifically, we extend the model to support hierarchical event structures and let the model recognize point-cuts of aspect-oriented programming as events. We provide the event operators designed to specify the events on instances and handle temporal relations of the instances. It is presented that syntax and semantics of constructs in our event processing language including various and progressive event operators, complex event pattern, etc. In addition, an event context mechanism is proposed to analyze more delicate events. Finally, through application studies application possibility of this study would be shown and merits of this event model would be present through comparison with other event model.

The Effects of a Marine Leisure Exhibition Event's Appraisal Attributes on Visitors' Satisfaction and Re-visit Intention

  • Cho, Woo-Jeong
    • Journal of Navigation and Port Research
    • /
    • v.35 no.4
    • /
    • pp.335-342
    • /
    • 2011
  • The purposes of this study were to analyze the effects of a marine leisure exhibition event(MLEE)'s appraisal attributes on visitors' satisfaction and rep-visit intention and thus provide fundamental information that facilitates developing effective marketing and operational strategies for a MLEE. In order to accomplish such purposes, this study employed a survey with a total of 300 visitors to a MLEE hosted by G Province. Questionnaires were developed on the basis of related studies and modified to reflect the study context. Then, such questionnaires were verified to be valid and reliable through content validity, factor analysis and internal consistency analysis. Valid 286 questionnaires were analyzed with correlation analysis and multiple regression analysis on significance level of .05. Following findings were derived from current study. First of all, the appraisal attributes of a MLEE had a significant effect on visitors' satisfaction and among them only the factor of event program had a unique relation with the levels of satisfaction. In addition, the appraisal attributes of the MLEE also had a significant effect on visitors' rep-visit intention behavior and among them event program, transportation and employee factors had unique relations with the performance variable in order. In conclusion, all the research hypotheses that had been set up through previous studies were confirmed in this study.