A real-time GPU-based approach for alert aggregation

被引:0
|
作者
Abadi, Masoud [1 ]
Nowroozi, Alireza [1 ]
机构
[1] Malek Ashtar Univ Technol, IT Secur Inst, ICT Dept, Tehran, Iran
关键词
Alert aggregation; security alert; Graphics Processing Unit (GPU); snort; real-time cooperative model;
D O I
10.3233/JHS-150509
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Alert correlation is an approach to analyze a huge number of security alerts received from network sensors. An alert correlation engine normalizes, fuses and clusters incoming alerts; then identifies relationships among them. Limitation of computing resources, like CPUs, makes such systems not satisfactory. In recent years, GPUs have been used in various fields, however, due to the dynamic nature of processes and data structures in alert correlation, correlation algorithms have not been implemented on the GPU. This paper presents a novel approach to implement alert correlation on the GPU. It focuses on alert aggregation, which is classified as a similarity-based alert correlation. This approach presents an online cooperative model which utilizes the processing power of CPUs and GPUs to aggregate security alert. This paper also presents the development of a toolkit named GTA2, which works as an assistant tool with Snort and provides online alert aggregation on alerts received. GTA2 takes advantage of unused processing power of existing GPU to aggregate security alerts generated by Snort. Evaluations illustrate the proposed method will improve the processing speed by 15 times.
引用
收藏
页码:69 / 80
页数:12
相关论文
共 50 条
  • [21] A novel GPU-based sonar simulator for real-time applications
    Cerqueira, Romulo
    Trocoli, Tiago
    Neves, Gustavo
    Joyeux, Sylvain
    Albiez, Jan
    Oliveira, Luciano
    [J]. COMPUTERS & GRAPHICS-UK, 2017, 68 : 66 - 76
  • [22] Using GPU-Based Ray Tracing for Real-Time Composition in the Real Scene
    Bae, Sungmin
    Hwang, Kyunghee
    Hong, Hyunki
    [J]. ADVANCES IN MULTIMEDIA INFORMATION PROCESSING - PCM 2008, 9TH PACIFIC RIM CONFERENCE ON MULTIMEDIA, 2008, 5353 : 80 - 88
  • [23] A GPU-Based Architecture for Real-Time Data Assessment at Synchrotron Experiments
    Chilingaryan, Suren
    Mirone, Alessandro
    Hammersley, Andrew
    Ferrero, Claudio
    Helfen, Lukas
    Kopmann, Andreas
    Rolo, Tomy dos Santos
    Vagovic, Patrik
    [J]. IEEE TRANSACTIONS ON NUCLEAR SCIENCE, 2011, 58 (04) : 1447 - 1455
  • [24] GPU-Based Parallel Collision Detection for Real-Time Motion Planning
    Pan, Jia
    Manocha, Dinesh
    [J]. ALGORITHMIC FOUNDATIONS OF ROBOTICS IX, 2010, 68 : 211 - 228
  • [25] GPU-Based Real-Time Imaging Software Suite for Medical Ultrasound
    Choe, Jung Woo
    Nikoozadeh, Amin
    Oralkan, Omer
    Khuri-Yakub, Butrus T.
    [J]. 2013 IEEE INTERNATIONAL ULTRASONICS SYMPOSIUM (IUS), 2013, : 2057 - 2060
  • [26] GPU-based implementation of a real-time model for atmospheric dispersion of radionuclides
    Santos, Marcelo C.
    Pinheiro, Andre
    Schirru, Roberto
    Pereira, Claudio M. N. A.
    [J]. PROGRESS IN NUCLEAR ENERGY, 2019, 110 : 245 - 259
  • [27] Real-Time GPU-Based Voxel Carving with Systematic Occlusion Handling
    Schick, Alexander
    Stiefelhagen, Rainer
    [J]. PATTERN RECOGNITION, PROCEEDINGS, 2009, 5748 : 372 - 381
  • [28] Real-time GPU-based Face Detection in HD Video Sequences
    Oro, David
    Fernandez, Carles
    Rodriguez Saeta, Javier
    Martorell, Xavier
    Hernando, Javier
    [J]. 2011 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION WORKSHOPS (ICCV WORKSHOPS), 2011,
  • [29] Real-time eye blink detection with GPU-based SIFT tracking
    Lalonde, Marc
    Byrns, David
    Gagnon, Langis
    Teasdale, Normand
    Laurendeau, Denis
    [J]. FOURTH CANADIAN CONFERENCE ON COMPUTER AND ROBOT VISION, PROCEEDINGS, 2007, : 481 - +
  • [30] A GPU-Based Real-Time Traffic Sign Detection and Recognition System
    Chen, Zhilu
    Huang, Xinming
    Ni, Zhen
    He, Haibo
    [J]. 2014 IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE IN VEHICLES AND TRANSPORTATION SYSTEMS (CIVTS), 2014, : 1 - 5