MATATABI: Multi-layer Threat Analysis Platform with Hadoop

2014 Third International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS)(2014)

引用 7|浏览5
暂无评分
摘要
Threat detection and analysis are indispensable processes in today's cyberspace, but current state of the art threat detection is still limited to specific aspects of modern malicious activities due to the lack of information to analyze. By measuring and collecting various types of data, from traffic information to human behavior, at different vantage points for a long duration, the viewpoint seems to be helpful to deeply inspect threats, but faces scalability issues as the amount of collected data grows, since more computational resources are required for the analysis. In this paper, we report our experience from operating the Hadoop platform, called MATATABI, for threat detections, and present the micro-benchmarks with four different backends of data processing in typical use cases such as log data and packet trace analysis. The benchmarks demonstrate the advantages of distributed computation in terms of performance. Our extensive use cases of analysis modules showcase the potential benefit of deploying our threat analysis platform.
更多
查看译文
关键词
MATATABI,multilayer threat analysis platform,threat detection,cyberspace,traffic information,human behavior,scalability issues,Hadoop platform,micro-benchmarks,data processing,distributed computation
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要