Logic-Driven Cybersecurity: A Novel Framework for System Log Anomaly Detection using Answer Set Programming

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Li, Fang, Zuo, Fei, Gupta, Gopal
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915654048677888
author Li, Fang
Zuo, Fei
Gupta, Gopal
author_facet Li, Fang
Zuo, Fei
Gupta, Gopal
contents This study explores the application of Answer Set Programming (ASP) for detecting anomalies in system logs, addressing the challenges posed by evolving cyber threats. We propose a novel framework that leverages ASP's declarative nature and logical reasoning capabilities to encode complex security rules as logical predicates. Our ASP-based system was applied to a real-world Linux system log dataset, demonstrating its effectiveness in identifying various anomalies such as potential brute-force attacks, privilege escalations, frequent network connections from specific IPs, and various system-level issues. Key findings highlight ASP's strengths in handling structured log data, rule flexibility, and event correlation. The approach shows promise in providing explainable alerts from real-world data. This research contributes to computer forensics by demonstrating a logic-based paradigm for log analysis on a practical dataset, opening avenues for more nuanced and adaptive cyber intelligence systems.
format Preprint
id arxiv_https___arxiv_org_abs_2512_04908
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Logic-Driven Cybersecurity: A Novel Framework for System Log Anomaly Detection using Answer Set Programming
Li, Fang
Zuo, Fei
Gupta, Gopal
Cryptography and Security
Logic in Computer Science
This study explores the application of Answer Set Programming (ASP) for detecting anomalies in system logs, addressing the challenges posed by evolving cyber threats. We propose a novel framework that leverages ASP's declarative nature and logical reasoning capabilities to encode complex security rules as logical predicates. Our ASP-based system was applied to a real-world Linux system log dataset, demonstrating its effectiveness in identifying various anomalies such as potential brute-force attacks, privilege escalations, frequent network connections from specific IPs, and various system-level issues. Key findings highlight ASP's strengths in handling structured log data, rule flexibility, and event correlation. The approach shows promise in providing explainable alerts from real-world data. This research contributes to computer forensics by demonstrating a logic-based paradigm for log analysis on a practical dataset, opening avenues for more nuanced and adaptive cyber intelligence systems.
title Logic-Driven Cybersecurity: A Novel Framework for System Log Anomaly Detection using Answer Set Programming
topic Cryptography and Security
Logic in Computer Science
url https://arxiv.org/abs/2512.04908