Value, Message, Distribution, Powerset, Thread
This lesson introduces the following analysis patterns: abnormal value, error message, error distribution, error powerset, and error thread.
We'll cover the following
Abnormal value
While preparing a presentation on malware narratives, we found one essential pattern missing from the current log analysis pattern catalog. Most of the time, we see some abnormal or unexpected value in a software trace or log, such as a network address outside the expected range, which triggers a further investigation. The message structure may have the same message invariant, but the variable part may contain such values as depicted graphically below:
Get hands-on with 1300+ tech skills courses.