首页> 外文会议>IEEE International Performance Computing and Communications Conference >Parallel and distributed normalization of security events for instant attack analysis
【24h】

Parallel and distributed normalization of security events for instant attack analysis

机译:安全事件的并行和分布式规范化,可用于即时攻击分析

获取原文

摘要

When looking at media reports nowadays, major security breaches of big companies and governments seem to be a normal situation. An important step for the investigation or even prevention of these breaches is to normalize and analyze security-related log events from various systems in the target network. However, the number of log events produced in big IT landscapes can grow up to multiple billions per day. Current log management solutions, e.g., Security Information and Event Management (SIEM), cannot even closely normalize such huge amounts of data and therefore disable the tracking of attacks in real-time, which means that the log data remains unusable for attack analysis. In this paper, we present an approach to fully normalize event logs in high-speed by making use of established high-performance inter-thread messaging in conjunction with a hierarchical knowledge-base of log formats and parallel processing on multiple low-end systems. Using our approach, we are able to process more than 250,000 events/sec on relatively low-profile machines and can therefore easily handle more than 20 billion events/day, which is enough to handle average and peek loads of log events from big enterprise networks.
机译:如今,当查看媒体报道时,大公司和政府的重大安全漏洞似乎是正常情况。调查甚至预防这些漏洞的重要步骤是标准化和分析来自目标网络中各种系统的与安全相关的日志事件。但是,在大型IT环境中产生的日志事件的数量每天可能会增长到数十亿。当前的日志管理解决方案,例如安全信息和事件管理(SIEM),甚至不能紧密规范化如此大量的数据,因此无法实时跟踪攻击,这意味着日志数据仍然无法用于攻击分析。在本文中,我们提出一种方法,通过利用已建立的高性能线程间消息传递,日志格式的分层知识库以及在多个低端系统上的并行处理,来完全规范事件日志。使用我们的方法,我们能够在相对低调的计算机上每秒处理超过250,000个事件,因此每天可以轻松处理超过200亿个事件,足以处理来自大型企业网络的平均和窥探日志事件负载。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号