Towards an Open Format for Scalable System Telemetry

被引:3
|
作者
Taylor, Teryl [1 ]
Araujo, Frederico [1 ]
Shu, Xiaokui [1 ]
机构
[1] IBM Res, Yorktown Hts, NY 10598 USA
关键词
telemetry; open standard; data representation; system monitoring; threat detection;
D O I
10.1109/BigData50022.2020.9378294
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A data representation for system behavior telemetry for scalable big data security analytics is presented, affording telemetry consumers comprehensive visibility into workloads at reduced storage and processing overheads. The new abstraction, SysFlow, is a compact open data format that lifts the representation of system activities into a flow-centric, object-relational mapping that records how applications interact with their environment, relating processes to file accesses, network activities, and runtime information. The telemetry format supports single-event and volumetric flow representations of process control flows, file interactions, and network communications. Evaluation on enterprise-grade benchmarks shows that SysFlow facilitates deeper introspection into attack kill chains while yielding traces orders of magnitude smaller than current state-of-the-art system telemetry approaches-drastically reducing storage requirements and enabling feature-filled system analytics, process-level provenance tracking, and long-term data archival for cyber threat discovery and forensic analysis on historical data.
引用
收藏
页码:1031 / 1040
页数:10
相关论文
共 50 条
  • [1] IntStream: Towards Flexible, Expressive, and Scalable Network Telemetry
    Cheng, Xin
    Wang, Zhiliang
    Zhang, Shize
    He, Xin
    Yang, Jiahai John
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (03): : 2854 - 2868
  • [2] RIPPLE: Scalable Medical Telemetry System for Supporting Combat Rescue
    Renner, Adam
    Williams, Robert
    Harmon, Brandon
    Ganapathy, Subhashini
    Abhyankar, Kushal
    West, James
    Weiner, Nir
    Weinle, Nathan
    McCartney, Matthew
    Boswell, Lucas
    IEEE NATIONAL AEROSPACE AND ELECTRONICS CONFERENCE (NAECON 2014), 2014, : 228 - 232
  • [3] Towards an Open Archival Information System Compliant Exchange Format to Ensure Reproducibility of Assays in Cancer Care
    Engel, F.
    Walsh, P.
    Goerzig, H.
    Brocks, H.
    Heutelbeck, D.
    Kelly, Brian
    Fuchs, M.
    Hemmje, M.
    XIV MEDITERRANEAN CONFERENCE ON MEDICAL AND BIOLOGICAL ENGINEERING AND COMPUTING 2016, 2016, 57 : 775 - 780
  • [4] FullSight: Towards Scalable, High-Coverage, and Fine-grained Network Telemetry
    Ling, Sen
    Liu, Waixi
    Zhu, Yinghao
    Tan, Miaoquan
    Huang, Jieming
    Guo, Zhenzheng
    Lin, Wenhong
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 263 - 270
  • [5] Open Trace Format 2 The Next Generation of Scalable Trace Formats and Support Libraries
    Eschweiler, Dominic
    Wagner, Michael
    Geimer, Markus
    Knuepfer, Andreas
    Nagel, Wolfgang E.
    Wolf, Felix
    APPLICATIONS, TOOLS AND TECHNIQUES ON THE ROAD TO EXASCALE COMPUTING, 2012, 22 : 481 - 490
  • [6] Towards Performance Tooling Interoperability: An Open Format for Representing Execution Traces
    Okanovic, Dusan
    van Hoorn, Andre
    Heger, Christoph
    Wert, Alexander
    Siegl, Stefan
    COMPUTER PERFORMANCE ENGINEERING, 2016, 9951 : 94 - 108
  • [7] DEPOS - A FORMAT INDEPENDENT DECOMMUTATION AND DATA COMPRESSION SYSTEM FOR HIGH-SPEED TELEMETRY
    COSGROVE, JD
    HOWARD, LM
    TOWNSEND, TJ
    IEEE COMPUTER GROUP NEWS, 1969, 2 (09): : 3 - &
  • [8] The Open Data Format and Query System of the Sensing Web
    Mitsuda, Naruki
    Ajisaka, Tsuneo
    INFORMATION PROCESSING AND MANAGEMENT OF UNCERTAINTY IN KNOWLEDGE-BASED SYSTEMS: APPLICATIONS, PT II, 2010, 81 : 680 - 689
  • [9] A Scalable Privacy Preserving System for Open Data
    Yeh, Chao-Chun
    Wang, Pang-Chieh
    Pan, Yu-Hsuan
    Kao, Ming-Chih
    Huang, Shih-Kun
    2016 INTERNATIONAL COMPUTER SYMPOSIUM (ICS), 2016, : 312 - 317
  • [10] Towards a scalable refereeing system for online gaming
    Veron, Maxime
    Marin, Olivier
    Monnet, Sebastien
    Guessoum, Zahia
    2012 11TH ANNUAL WORKSHOP ON NETWORK AND SYSTEMS SUPPORT FOR GAMES (NETGAMES), 2012,