首页> 外文会议>IEEE International Performance Computing and Communications Conference >Parallel and distributed normalization of security events for instant attack analysis
【24h】

Parallel and distributed normalization of security events for instant attack analysis

机译:即时攻击分析的安全事件的并行和分布式标准化

获取原文
获取外文期刊封面目录资料

摘要

When looking at media reports nowadays, major security breaches of big companies and governments seem to be a normal situation. An important step for the investigation or even prevention of these breaches is to normalize and analyze security-related log events from various systems in the target network. However, the number of log events produced in big IT landscapes can grow up to multiple billions per day. Current log management solutions, e.g., Security Information and Event Management (SIEM), cannot even closely normalize such huge amounts of data and therefore disable the tracking of attacks in real-time, which means that the log data remains unusable for attack analysis. In this paper, we present an approach to fully normalize event logs in high-speed by making use of established high-performance inter-thread messaging in conjunction with a hierarchical knowledge-base of log formats and parallel processing on multiple low-end systems. Using our approach, we are able to process more than 250,000 events/sec on relatively low-profile machines and can therefore easily handle more than 20 billion events/day, which is enough to handle average and peek loads of log events from big enterprise networks.
机译:在现在看待媒体报道时,大公司和政府的主要安全违规似乎是正常情况。调查或甚至预防这些违规的一个重要步骤是从目标网络中的各种系统正常化和分析安全相关的日志事件。但是,大IT景观中产生的日志事件数量每天可以长到多个数十亿。当前日志管理解决方案,例如,安全信息和事件管理(SIEM),甚至无法充分归一化如此大量的数据,因此禁用实时攻击,这意味着日志数据对攻击分析保持不可用。在本文中,我们通过利用建立的高性能间线程传递与多个低端系统上的分层知识库以及多个低端系统上的并行处理一起使用建立的高性能间通信来介绍一种完全正常化事件日志的方法。使用我们的方法,我们能够在相对较低的机器上处理超过250,000个事件/秒,因此可以轻松处理超过20亿的活动/日,这足以处理大型企业网络的平均和偷看的日志事件。 。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号