| | |
| | |
Stat |
Members: 3645 Articles: 2'504'928 Articles rated: 2609
25 April 2024 |
|
| | | |
|
Article overview
| |
|
A Streaming Analytics Language for Processing Cyber Data | Eric L. Goodman
; Dirk Grunwald
; | Date: |
3 Nov 2019 | Abstract: | We present a domain-specific language called SAL(the Streaming Analytics
Language) for processing data in a semi-streaming model. In particular we
examine the use case of processing netflow data in order to identify malicious
actors within a network. Because of the large volume of data generated from
networks, it is often only feasible to process the data with a single pass,
utilizing a streaming (O(polylog n) space requirements) or semi-streaming
computing model ( O(n polylog n) space requirements). Despite these
constraints, we are able to achieve an average of 0.87 for the AUC of the ROC
curve for a set of situations dealing with botnet detection. The implementation
of an interpreter for SAL, which we call SAM (Streaming Analytics Machine),
achieves scaling results that show improved throughput to 61 nodes (976 cores),
with an overall rate of 373,000 netflows per second or 32.2 billion per day.
SAL provides a succinct way to describe common analyses that allow cyber
analysts to find data of interest, and SAM is a scalable interpreter of the
language. | Source: | arXiv, 1911.0815 | Services: | Forum | Review | PDF | Favorites |
|
|
No review found.
Did you like this article?
Note: answers to reviews or questions about the article must be posted in the forum section.
Authors are not allowed to review their own article. They can use the forum section.
browser Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
|
| |
|
|
|
| News, job offers and information for researchers and scientists:
| |