首页> 外文会议>49th Annual IEEE International Carnahan Conference on Security Technology >Distributed multistage alert correlation architecture based on Hadoop
【24h】

Distributed multistage alert correlation architecture based on Hadoop

机译:基于Hadoop的分布式多级警报关联架构

获取原文
获取原文并翻译 | 示例

摘要

There are three main approaches to design when implementing an alert correlation architecture; these are centralised, hierarchical, and decentralised. Centralised approaches benefit from simplicity of implementation and high algorithm expressiveness, but suffer in terms of scalability. The scalability issue is alleviated with hierarchical and decentralised approaches, but this comes at a cost of additional implementation complexity and lower algorithm quality. Introduced is a new alert correlation architecture based on Hadoop. The developed architecture allows for greater scalability whilst maintaining algorithm expressiveness and design simplicity. It incorporates alert aggregation, verification, and correlation components, which together provide for a clear and succinct view of potentially malicious activity. Each component was tested against a series of datasets that represent potential real world scenarios across a cluster of varying size. The results demonstrate that all components in the architecture have the ability to scale across many nodes in a cluster, allowing for the processing of large and complex attack scenarios in a timely manner.
机译:实施警报关联体系结构时,主要有三种设计方法:这些是集中的,分层的和分散的。集中式方法受益于实现的简单性和较高的算法表达性,但在可伸缩性方面受到影响。通过分层和分散的方法可以缓解可伸缩性问题,但这是以增加实现复杂性和降低算法质量为代价的。引入了一种基于Hadoop的新警报关联架构。开发的体系结构可实现更大的可扩展性,同时保持算法的可表达性和设计简单性。它结合了警报聚合,验证和关联组件,它们一起提供了对潜在恶意活动的清晰简洁的视图。每个组件都针对一系列数据集进行了测试,这些数据集代表了大小可变的集群中潜在的现实世界场景。结果表明,体系结构中的所有组件都可以跨集群中的许多节点进行扩展,从而可以及时处理大型复杂攻击场景。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号