Publisher DOI: | 10.1145/2740070.2631471 | Title: | Native actors : how to scale network forensics | Language: | English | Authors: | Vallentin, Matthias Charousset, Dominik Schmidt, Thomas C. Paxson, Vern Wählisch, Matthias |
Keywords: | Security; Network Forensics; Message-oriented Middleware | Issue Date: | 2014 | Publisher: | Association for Computing Machinery (ACM) | Part of Series: | Proceedings of the SIGCOMM Chicago 2014 & the best of the co-located workshops | Journal or Series Name: | ACM SIGCOMM computer communication review | Volume: | 44 | Issue: | 4 | Startpage: | 141 | Endpage: | 142 | Conference: | SIGCOMM Chicago 2014 | Abstract: | When an organization detects a security breach, it undertakes a forensic analysis to figure out what happened. This investigation involves inspecting a wide range of heterogeneous data sources spanning over a long period of time. The iterative nature of the analysis procedure requires an interactive experience with the data. However, the distributed processing paradigms we find in practice today fail to provide this requirement: the batch-oriented nature of MapReduce cannot deliver sub-second round-trip times, and distributed in-memory processing cannot store the terabytes of activity logs needed to inspect during an incident. We present the design and implementation of Visibility Across Space and Time~(VAST), a distributed database to support interactive network forensics, and libcppa, its exceptionally scalable messaging core. The extended actor framework libcppa enables VAST to distribute lightweight tasks at negligible overhead. In our live demo, we showcase how VAST enables security analysts to grapple with the huge amounts of data often associated with incident investigations. |
URI: | http://hdl.handle.net/20.500.12738/913 | ISSN: | 0146-4833 | Review status: | Unknown / not specified | Institute: | Department Informatik Fakultät Technik und Informatik |
Type: | Chapter/Article (Proceedings) |
Appears in Collections: | Publications without full text |
Show full item record
Add Files to Item
Note about this record
Export
Items in REPOSIT are protected by copyright, with all rights reserved, unless otherwise indicated.