NodeMerge: Template Based Efficient Data Reduction For Big-Data Causality Analysis

被引:57
|
作者
Tang, Yutao [2 ]
Li, Ding [1 ]
Li, Zhichun [1 ]
Zhang, Mu [3 ]
Jee, Kangkook [1 ]
Xiao, Xusheng [4 ]
Wu, Zhenyu [1 ]
Rhee, Junghwan [1 ]
Xu, Fengyuan [5 ]
Li, Qun [2 ]
机构
[1] NEC Labs Amer Inc, Princeton, NJ 08540 USA
[2] Coll William & Mary, Williamsburg, VA 23187 USA
[3] Cornell Univ, Ithaca, NY 14853 USA
[4] Case Western Reserve Univ, Cleveland, OH 44106 USA
[5] Nanjing Univ, Natl Key Lab Novel Software Technol, Nanjing, Jiangsu, Peoples R China
关键词
Security; Data Reduction;
D O I
10.1145/3243734.3243763
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Today's enterprises are exposed to sophisticated attacks, such as Advanced Persistent Threats (APT) attacks, which usually consist of stealthy multiple steps. To counter these attacks, enterprises often rely on causality analysis on the system activity data collected from a ubiquitous system monitoring to discover the initial penetration point, and from there identify previously unknown attack steps. However, one major challenge for causality analysis is that the ubiquitous system monitoring generates a colossal amount of data and hosting such a huge amount of data is prohibitively expensive. Thus, there is a strong demand for techniques that reduce the storage of data for causality analysis and yet preserve the quality of the causality analysis. To address this problem, in this paper, we propose NodeMerge, a template based data reduction system for online system event storage. Specifically, our approach can directly work on the stream of system dependency data and achieve data reduction on the read-only file events based on their access patterns. It can either reduce the storage cost or improve the performance of causality analysis under the same budget. Only with a reasonable amount of resource for online data reduction, it nearly completely preserves the accuracy for causality analysis. The reduced form of data can be used directly with little overhead. To evaluate our approach, we conducted a set of comprehensive evaluations, which show that for different categories of workloads, our system can reduce the storage capacity of raw system dependency data by as high as 75.7 times, and the storage capacity of the state-of-the-art approach by as high as 32.6 times. Furthermore, the results also demonstrate that our approach keeps all the causality analysis information and has a reasonably small overhead in memory and hard disk.
引用
收藏
页码:1324 / 1337
页数:14
相关论文
共 50 条
  • [31] Big-data based infrastructure management: toward Assetmetrics
    Kobayashi, K.
    Kaito, K.
    LIFE-CYCLE OF STRUCTURAL SYSTEMS: DESIGN, ASSESSMENT, MAINTENANCE AND MANAGEMENT, 2015, : 70 - 80
  • [32] Big-data platform based on open source ecosystem
    Lei J.
    Ye H.
    Wu Z.
    Zhang P.
    Xie L.
    He Y.
    1600, Science Press (54): : 80 - 93
  • [33] A measurement-based study of big-data movement
    Addanki, Ranjana
    Maji, Sourav
    Veeraraghavan, Malathi
    Tracy, Chris
    2015 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2015, : 445 - 449
  • [34] Towards efficient data exchange and sharing for big-data driven materials science: metadata and data formats
    Ghiringhelli, Luca M.
    Carbogno, Christian
    Levchenko, Sergey
    Mohamed, Fawzi
    Huhs, Georg
    Luders, Martin
    Oliveira, Micael
    Scheffler, Matthias
    NPJ COMPUTATIONAL MATERIALS, 2017, 3
  • [35] Data Modifications in Blockchain Architecture for Big-Data Processing
    Tulkinbekov, Khikmatullo
    Kim, Deok-Hwan
    SENSORS, 2023, 23 (21)
  • [36] A big-data processing framework for uncertainties in transportation data
    Yang, Jie
    Ma, Jun
    2015 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS (FUZZ-IEEE 2015), 2015,
  • [37] ConEx: Efficient Exploration of Big-Data System Configurations for Better Performance
    Krishna, Rahul
    Tang, Chong
    Sullivan, Kevin
    Ray, Baishakhi
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (03) : 893 - 909
  • [38] Becoming data-savvy in a big-data world
    Xu, Meng
    Rhee, Seung Yon
    TRENDS IN PLANT SCIENCE, 2014, 19 (10) : 619 - 622
  • [39] Voter Privacy and Big-Data Elections
    Judge, Elizabeth F.
    Pal, Michael
    OSGOODE HALL LAW JOURNAL, 2021, 58 (01): : 1 - 55
  • [40] Efficient Storage of Big-Data for Real-Time GPS Applications
    Akulakrishna, Pavan Kumar
    Lakshmi, J.
    Nandy, S. K.
    2014 IEEE FOURTH INTERNATIONAL CONFERENCE ON BIG DATA AND CLOUD COMPUTING (BDCLOUD), 2014, : 1 - 8