<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Log Data Management | COMSYS | RWTH Aachen University</title><link>https://www.comsys.rwth-aachen.de/tags/security-log-data-management/</link><atom:link href="https://www.comsys.rwth-aachen.de/tags/security-log-data-management/index.xml" rel="self" type="application/rss+xml"/><description>Security Log Data Management</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Mon, 04 May 2026 00:00:00 +0000</lastBuildDate><image><url>https://www.comsys.rwth-aachen.de/media/logo.svg</url><title>Security Log Data Management</title><link>https://www.comsys.rwth-aachen.de/tags/security-log-data-management/</link></image><item><title>Identifying Security-relevant Log Data for Long-Term Retention</title><link>https://www.comsys.rwth-aachen.de/openings/2026/2026-05-security-dt-logs/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://www.comsys.rwth-aachen.de/openings/2026/2026-05-security-dt-logs/</guid><description>&lt;h2 id="background"&gt;Background&lt;/h2&gt;
&lt;img src="telekom.png" style="margin: 10px 5%; width: 20%; float:right;"&gt;
&lt;p&gt;In increasingly digital and high-throughput networks, retaining log data for extended periods is crucial for incident response and forensic analysis.
Yet because truly malicious activity is rare relative to benign behavior, organizations often store massive volumes of logs only to discard them after a retention window (e.g., 12–16 months) without ever using them.
An intelligent approach that prioritizes security-relevant logs can preserve storage capacity, extend retention for truly valuable data, and concentrate analysis on information that matters during investigations.
In collaboration with Deutsche Telekom Technik, this thesis aims to define and operationalize &amp;ldquo;heightened interest&amp;rdquo; for logs, ensuring long-term retention is risk-aware, cost-effective, and aligned with incident response needs.&lt;/p&gt;
&lt;h2 id="your-approach"&gt;Your Approach&lt;/h2&gt;
&lt;p&gt;This thesis will develop an AI-assisted framework for long-term log retention that prioritizes security relevance while respecting storage budgets and compliance requirements.
Building on modern Transformer‑based models (e.g., BERT or domain variants like LogBERT), complemented by selectively used LLMs for normalization and analyst‑facing explanations, the approach estimates the significance of individual logs and their surrounding context.
These signals are combined with asset criticality, incident response needs, and storage constraints to drive a transparent, budget-aware retention policy that keeps high-value events (and relevant context windows) for longer, while judiciously downsampling lower-value records within regulatory bounds.&lt;/p&gt;
&lt;h2 id="what-we-offer"&gt;What we offer&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The opportunity to address cutting-edge &lt;strong&gt;security challenges&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;This thesis is in collaboration with Deutsche Telekom Technik GmbH, which will support the thesis with &lt;strong&gt;real-world data&lt;/strong&gt; and &lt;strong&gt;expert knowledge from cybersecurity professionals&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-we-expect"&gt;What we expect&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Good understanding of &lt;strong&gt;machien learning techniques&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Solid programming skills (preferably in Python)&lt;/li&gt;
&lt;li&gt;Experience with the &lt;strong&gt;Transformers/LLMs&lt;/strong&gt; is a plus, but not mandatory&lt;/li&gt;
&lt;li&gt;Ability to work independently and &lt;strong&gt;communicate effectively and regularly&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="contact--application"&gt;Contact &amp;amp; Application&lt;/h2&gt;
&lt;p&gt;If you are interested, please send a brief motivation explaining how your skills fit the topic and your transcript of records via email.&lt;/p&gt;</description></item></channel></rss>