Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks
As more and more Internet-based attacks arise, organiza-tions are responding by deploying an assortment of security products that generate situational intelligence in the form of logs. These logs often contain high volumes of inter-esting and useful information about activities in the net-work, and are among the first data sources that informa-tion security specialists consult when they suspect that an attack has taken place. However, security products often come from a patchwork of vendors, and are inconsistently installed and administered. They generate logs whose for-mats differ widely and that are often incomplete, mutually contradictory, and very large in volume. Hence, although this collected information is useful, it is often dirty. We present a novel system, Beehive, that attacks the prob-
