Verlagslink DOI: 10.1145/2740070.2631471
Titel: Native actors : how to scale network forensics
Sprache: Englisch
Autorenschaft: Vallentin, Matthias 
Charousset, Dominik 
Schmidt, Thomas C.  
Paxson, Vern 
Wählisch, Matthias 
Schlagwörter: Security; Network Forensics; Message-oriented Middleware
Erscheinungsdatum: 2014
Verlag: Association for Computing Machinery (ACM)
Teil der Schriftenreihe: Proceedings of the SIGCOMM Chicago 2014 & the best of the co-located workshops 
Zeitschrift oder Schriftenreihe: ACM SIGCOMM computer communication review 
Zeitschriftenband: 44
Zeitschriftenausgabe: 4
Anfangsseite: 141
Endseite: 142
Konferenz: SIGCOMM Chicago 2014 
Zusammenfassung: 
When an organization detects a security breach, it undertakes a forensic analysis to figure out what happened. This investigation involves inspecting a wide range of heterogeneous data sources spanning over a long period of time. The iterative nature of the analysis procedure requires an interactive experience with the data. However, the distributed processing paradigms we find in practice today fail to provide this requirement: the batch-oriented nature of MapReduce cannot deliver sub-second round-trip times, and distributed in-memory processing cannot store the terabytes of activity logs needed to inspect during an incident. We present the design and implementation of Visibility Across Space and Time~(VAST), a distributed database to support interactive network forensics, and libcppa, its exceptionally scalable messaging core. The extended actor framework libcppa enables VAST to distribute lightweight tasks at negligible overhead. In our live demo, we showcase how VAST enables security analysts to grapple with the huge amounts of data often associated with incident investigations.
URI: http://hdl.handle.net/20.500.12738/913
ISSN: 0146-4833
Begutachtungsstatus: Unbekannt / keine Angabe
Einrichtung: Department Informatik 
Fakultät Technik und Informatik 
Dokumenttyp: Konferenzveröffentlichung
Enthalten in den Sammlungen:Publications without full text

Zur Langanzeige

Seitenansichten

90
checked on 26.12.2024

Google ScholarTM

Prüfe

HAW Katalog

Prüfe

Volltext ergänzen

Feedback zu diesem Datensatz


Alle Ressourcen in diesem Repository sind urheberrechtlich geschützt.