UIUC Office of Technology Management
Published on UIUC Office of Technology Management (https://origin.otm.illinois.edu)

Home > Transparent Interpretation and Integration of Layered Software Architecture Event Streams

ωLog: Transparent Interpretation and Integration of Layered Software Architecture Event Streams

Transparent Interpretation and Integration of Layered Software Architecture Event Streams [1]

Prof. Bates at the University of Illinois has developed ωLog, a software application which collects application context through analysis of event logs, and integrates that information into whole-system provenance. Through binary analysis, ωLog determines application logging behavior, associates events at the application level with events at the system level, and based on user queries, generates a concise, semantically-rich, execution-partitioned provenance graph.  

ωLog addresses limitations in overhead costs, with an average of 12% runtime overhead, and does not require instrumentation.  Additionally, ωLog  provides forensically-relevant semantic information that other provenance systems cannot provide. ωLog provides system administrators an unprecedented wealth of information for tracing suspicious activity to the root cause, which is particularly useful in identifying and responding to Advanced Persistent Threats.

Applications

Security Information and Event Management (SIEM), cybersecurity

Adam M
Bates

Inventors:

The Office of Technology Management
319 Ceramics Building
105 South Goodwin Avenue
Urbana, IL 61801
Phone: 217.333.7862
Fax: 217.265.5530
Email: otm@illinois.edu

Source URL:https://origin.otm.illinois.edu/technologies/transparent-interpretation-and-integration-layered-software-architecture-event-streams

Links
[1] https://origin.otm.illinois.edu/technologies/transparent-interpretation-and-integration-layered-software-architecture-event-streams