A real-time GPU-based approach for alert aggregation

被引:0
|
作者
Abadi, Masoud [1 ]
Nowroozi, Alireza [1 ]
机构
[1] Malek Ashtar Univ Technol, IT Secur Inst, ICT Dept, Tehran, Iran
关键词
Alert aggregation; security alert; Graphics Processing Unit (GPU); snort; real-time cooperative model;
D O I
10.3233/JHS-150509
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Alert correlation is an approach to analyze a huge number of security alerts received from network sensors. An alert correlation engine normalizes, fuses and clusters incoming alerts; then identifies relationships among them. Limitation of computing resources, like CPUs, makes such systems not satisfactory. In recent years, GPUs have been used in various fields, however, due to the dynamic nature of processes and data structures in alert correlation, correlation algorithms have not been implemented on the GPU. This paper presents a novel approach to implement alert correlation on the GPU. It focuses on alert aggregation, which is classified as a similarity-based alert correlation. This approach presents an online cooperative model which utilizes the processing power of CPUs and GPUs to aggregate security alert. This paper also presents the development of a toolkit named GTA2, which works as an assistant tool with Snort and provides online alert aggregation on alerts received. GTA2 takes advantage of unused processing power of existing GPU to aggregate security alerts generated by Snort. Evaluations illustrate the proposed method will improve the processing speed by 15 times.
引用
收藏
页码:69 / 80
页数:12
相关论文
共 50 条
  • [1] GPU-based real-time crowd rendering
    Zhang, Yong
    Yin, Bao-Cai
    Kong, De-Hui
    Yang, Guang-Wei
    [J]. Beijing Gongye Daxue Xuebao / Journal of Beijing University of Technology, 2009, 35 (10): : 1434 - 1440
  • [2] GPU-based Real-time Face Detector
    Jeong, Jae-chan
    Shin, Ho-chul
    Cho, Jae-il
    [J]. 2012 9TH INTERNATIONAL CONFERENCE ON UBIQUITOUS ROBOTS AND AMBIENT INTELLIGENCE (URAL), 2012, : 173 - 175
  • [3] GPU-based real-time deformation with normal reconstruction
    Che, Yinghui
    Wang, Jing
    Liang, Xiaohui
    [J]. TECHNOLOGIES FOR E-LEARNING AND DIGITAL ENTERTAINMENT, PROCEEDINGS, 2007, 4469 : 667 - +
  • [4] Real-time GPU-based simulation of dynamic terrain
    Aquilio, Anthony S.
    Brooks, Jeremy C.
    Zhu, Ying
    Owen, G. Scott
    [J]. ADVANCES IN VISUAL COMPUTING, PT 1, 2006, 4291 : 891 - +
  • [5] GPU-based real-time RGBD data filtering
    Abdenour Amamra
    Nabil Aouf
    [J]. Journal of Real-Time Image Processing, 2018, 14 : 323 - 340
  • [6] GPU-based real-time RGBD data filtering
    Amamra, Abdenour
    Aouf, Nabil
    [J]. JOURNAL OF REAL-TIME IMAGE PROCESSING, 2018, 14 (02) : 323 - 340
  • [7] GPU-based real-time acoustical occlusion modeling
    Cowan, Brent
    Kapralos, Bill
    [J]. VIRTUAL REALITY, 2010, 14 (03) : 183 - 196
  • [8] GPU-based real-time acoustical occlusion modeling
    Brent Cowan
    Bill Kapralos
    [J]. Virtual Reality, 2010, 14 : 183 - 196
  • [9] GPU-based bistatic ISAR real-time imaging
    Zhang, Chengyan
    Xie, Min
    Fu, Xiongjun
    Liu, Shiliang
    Wang, Wenqing
    [J]. 2015 IEEE 5TH ASIA-PACIFIC CONFERENCE ON SYNTHETIC APERTURE RADAR (APSAR), 2015, : 112 - 116
  • [10] GPU-Based Real-Time Range Image Segmentation
    Jin, Xinhua
    Kang, Dong Joong
    Jeong, Mun-Ho
    [J]. INTELLIGENT COMPUTING METHODOLOGIES, 2014, 8589 : 293 - 297