谷歌Chrome浏览器插件
订阅小程序
在清言上使用

Evaluation of the data handling pipeline of the ASTRID framework

2022 IEEE 8th International Conference on Network Softwarization (NetSoft)(2022)

引用 0|浏览2
暂无评分
摘要
Effective attack detection and security analytics rely on the availability of timely and fine-grained information about the evolving context of the protected environment. The data handling process entails collection from heterogeneous sources, local aggregation and transformation operations before transmission, and finally collection and delivery to multiple processing engines for analysis and correlation. Many Security Information and Event Management (SIEM) tools work according to the “funnel” principle: gather as much data as possible and then filter it to keep the relevant information. However, this might lead to unacceptable overhead, especially when monitoring containerized environments. As part of our activity in ASTRID, we therefore conducted experimental investigation on resource consumption of the data handling pipeline, starting from embedded agents up to delivery to the Context Broker.
更多
查看译文
关键词
Elastic stack,containers,monitoring,Kafka
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要