United We Log, Divided We Identify: A Decentralized Approach for Automated Log Analysis
Centralizing sensitive log data on a single analysis server for threat detection compounds security risk and creates a dangerous single point of failure. This paper presents Federated LogTracer, a decentralized log-analysis system that overcomes these shortcomings by combining an advanced parse-graph generation technique with federated learning. The system efficiently extracts meaningful contextual information from raw logs with minimal manual effort while ensuring sensitive log data remains localized to each participating organization, safeguarding privacy without sacrificing the collaborative benefits of pooled threat intelligence.
