【24h】

Multi-core Supported High Performance Security Analytics

机译:多核支持的高性能安全分析

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Such information as system and application logs as well as the output from the deployed security measures, e.g., IDS alerts, firewall logs, scanning reports, etc., is important for the administrators or security operators to be aware at first time of the running state of the system and take efforts if necessary. In this context, high performance security analytics is proposed to address the challenges to rapidly gather, manage, process, and analyze the large amount of real-time information generated from the large scale of enterprise IT-Infrastructure while it is being operated. As an example of next generation Security Information and Event Management (SIEM) platform, Security Analytics Lab (SAL) has been designed and implemented based on the newly emerged In-Memory data management technique, which makes it possible to efficiently organize and access different types of event information through a consistent central storage and interface. To correlate the information from different sources and identify the meaningful information is another challenging task, which makes great sense for quickly judging the current situation and making the decision. In this paper, the multi-core processing technique is introduced in the SAL platform. Various correlation algorithms, e.g., k-means based algorithms, ROCK and QROCK clustering algorithms, have been implemented and integrated in the multi-core supported SAL architecture. Practical experiments are conducted and analyzed to proof that the performance of analytics can be significantly improved by applying multi-core processing technique in SAL.
机译:诸如系统和应用程序日志以及已部署的安全措施的输出之类的信息,例如IDS警报,防火墙日志,扫描报告等,对于管理员或安全操作员在第一时间了解运行状态非常重要。系统,并在必要时做出努力。在这种情况下,提出了高性能安全分析,以解决在运行时迅速收集,管理,处理和分析从大规模企业IT基础结构中生成的大量实时信息的挑战。作为下一代安全信息和事件管理(SIEM)平台的示例,已经基于新出现的内存数据管理技术设计和实施了安全分析实验室(SAL),这使得有效地组织和访问不同类型的数据成为可能通过一致的中央存储和界面收集事件信息。关联来自不同来源的信息并识别有意义的信息是另一项艰巨的任务,这对于快速判断当前情况并做出决策非常有意义。本文在SAL平台中介绍了多核处理技术。已实现各种相关算法,例如基于k均值的算法,ROCK和QROCK聚类算法,并将其集成到多核支持的SAL体系结构中。进行了实践实验并进行了分析,以证明通过在SAL中应用多核处理技术可以显着提高分析性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号