NodeMerge: Template Based Efficient Data Reduction For Big-Data Causality Analysis

被引:57
|
作者
Tang, Yutao [2 ]
Li, Ding [1 ]
Li, Zhichun [1 ]
Zhang, Mu [3 ]
Jee, Kangkook [1 ]
Xiao, Xusheng [4 ]
Wu, Zhenyu [1 ]
Rhee, Junghwan [1 ]
Xu, Fengyuan [5 ]
Li, Qun [2 ]
机构
[1] NEC Labs Amer Inc, Princeton, NJ 08540 USA
[2] Coll William & Mary, Williamsburg, VA 23187 USA
[3] Cornell Univ, Ithaca, NY 14853 USA
[4] Case Western Reserve Univ, Cleveland, OH 44106 USA
[5] Nanjing Univ, Natl Key Lab Novel Software Technol, Nanjing, Jiangsu, Peoples R China
关键词
Security; Data Reduction;
D O I
10.1145/3243734.3243763
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Today's enterprises are exposed to sophisticated attacks, such as Advanced Persistent Threats (APT) attacks, which usually consist of stealthy multiple steps. To counter these attacks, enterprises often rely on causality analysis on the system activity data collected from a ubiquitous system monitoring to discover the initial penetration point, and from there identify previously unknown attack steps. However, one major challenge for causality analysis is that the ubiquitous system monitoring generates a colossal amount of data and hosting such a huge amount of data is prohibitively expensive. Thus, there is a strong demand for techniques that reduce the storage of data for causality analysis and yet preserve the quality of the causality analysis. To address this problem, in this paper, we propose NodeMerge, a template based data reduction system for online system event storage. Specifically, our approach can directly work on the stream of system dependency data and achieve data reduction on the read-only file events based on their access patterns. It can either reduce the storage cost or improve the performance of causality analysis under the same budget. Only with a reasonable amount of resource for online data reduction, it nearly completely preserves the accuracy for causality analysis. The reduced form of data can be used directly with little overhead. To evaluate our approach, we conducted a set of comprehensive evaluations, which show that for different categories of workloads, our system can reduce the storage capacity of raw system dependency data by as high as 75.7 times, and the storage capacity of the state-of-the-art approach by as high as 32.6 times. Furthermore, the results also demonstrate that our approach keeps all the causality analysis information and has a reasonably small overhead in memory and hard disk.
引用
收藏
页码:1324 / 1337
页数:14
相关论文
共 50 条
  • [21] Neurotrauma as a big-data problem
    Huie, J. Russell
    Almeida, Carlos A.
    Ferguson, Adam R.
    CURRENT OPINION IN NEUROLOGY, 2018, 31 (06) : 702 - 708
  • [22] BigCache for Big-data Systems
    Roger, Michel Angelo
    Xu, Yiqi
    Zhao, Ming
    2014 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2014, : 189 - 194
  • [23] 'Big-Data' in dermatological research
    Kaliyadan, Feroze
    Chatterjee, Kingshuk
    INDIAN JOURNAL OF DERMATOLOGY VENEREOLOGY & LEPROLOGY, 2024, 90 (03): : 342 - 344
  • [24] Lessons for big-data projects
    Birney, Ewan
    NATURE, 2012, 489 (7414) : 49 - 51
  • [25] Big Data and Causality
    Hassani H.
    Huang X.
    Ghodsi M.
    Annals of Data Science, 2018, 5 (2) : 133 - 156
  • [26] Design and Implementation of Big-Data Analysis Application on Spark for Distribution Network Based on Data Interception
    Zhang, Pan
    Ding, Lingyun
    Jiang, Ning
    Ling, Wanshui
    Ding, Yi
    CLEANER ENERGY FOR CLEANER CITIES, 2018, 152 : 1170 - 1175
  • [27] Lessons for big-data projects
    Ewan Birney
    Nature, 2012, 489 : 49 - 51
  • [28] A review on sentiment discovery and analysis of educational big-data
    Han, Zhongmei
    Wu, Jiyi
    Huang, Changqin
    Huang, Qionghao
    Zhao, Meihua
    WILEY INTERDISCIPLINARY REVIEWS-DATA MINING AND KNOWLEDGE DISCOVERY, 2020, 10 (01)
  • [29] Big-Data analysis used NGS and study of evolution
    Ikeo, Kazuho
    GENES & GENETIC SYSTEMS, 2015, 90 (06) : 360 - 360
  • [30] Towards efficient data exchange and sharing for big-data driven materials science: metadata and data formats
    Luca M. Ghiringhelli
    Christian Carbogno
    Sergey Levchenko
    Fawzi Mohamed
    Georg Huhs
    Martin Lüders
    Micael Oliveira
    Matthias Scheffler
    npj Computational Materials, 3