针对高速网络环境下现有入侵防御系统(intrusion prevention system,IPS)日志采集速度和处理速度的不匹配、日志文件规模大而难以存储的问题,提出了采用循环缓冲队列的缓存机制,同步日志采集和处理操作方法。设计了预处理算法,删除冗余的日志记录,并使用极大文件集的日志存储策略,保存海量日志文件。实验结果表明,该方法适用于千兆网络环境,能够精简日志文件规模,保存更多的日志记录。
To resolve the problem of the mismatching speed between log gathering and processing,the storage of abundant log files in high-speed network environment,ring buffer scheme is proposed to synchronize operations of log gathering and log processing.Pre-processing algorithm is designed to delete redundancy log records and enormous file set is adapted to store the massive log files.Experiments demonstrate that the proposed method is applicable in the Gigabit network environment,shrinking the log files’ scale and saving the uttermost log records as well.