Effective attack detection and security analytics rely on the availability of timely and fine-grained information about the evolving context of the protected environment. The data han- dling process entails collection from heterogeneous sources, local aggregation and transformation operations before transmission, and finally collection and delivery to multiple processing engines for analysis and correlation. Many Security Information and Event Management (SIEM) tools work according to the "funnel" principle: gather as much data as possible and then filter it to keep the relevant information. However, this might lead to unacceptable overhead, especially when monitoring containerized environments. As part of our activity in ASTRID, we therefore conducted experimental inves- tigation on resource consumption of the data handling pipeline, starting from embedded agents up to delivery to the Context Broker.

Evaluation of the data handling pipeline of the ASTRID framework

Matteo Repetto;
2022

Abstract

Effective attack detection and security analytics rely on the availability of timely and fine-grained information about the evolving context of the protected environment. The data han- dling process entails collection from heterogeneous sources, local aggregation and transformation operations before transmission, and finally collection and delivery to multiple processing engines for analysis and correlation. Many Security Information and Event Management (SIEM) tools work according to the "funnel" principle: gather as much data as possible and then filter it to keep the relevant information. However, this might lead to unacceptable overhead, especially when monitoring containerized environments. As part of our activity in ASTRID, we therefore conducted experimental inves- tigation on resource consumption of the data handling pipeline, starting from embedded agents up to delivery to the Context Broker.
2022
Istituto di Matematica Applicata e Tecnologie Informatiche - IMATI -
Elastic stack
containers
monitoring
Kafka
File in questo prodotto:
File Dimensione Formato  
prod_466711-doc_183558.pdf

solo utenti autorizzati

Descrizione: Evaluation of the data handling pipeline of the ASTRID framework
Tipologia: Versione Editoriale (PDF)
Dimensione 187.45 kB
Formato Adobe PDF
187.45 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/444519
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact