Towards an Open Format for Scalable System Telemetry

被引:3
|
作者
Taylor, Teryl [1 ]
Araujo, Frederico [1 ]
Shu, Xiaokui [1 ]
机构
[1] IBM Res, Yorktown Hts, NY 10598 USA
关键词
telemetry; open standard; data representation; system monitoring; threat detection;
D O I
10.1109/BigData50022.2020.9378294
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A data representation for system behavior telemetry for scalable big data security analytics is presented, affording telemetry consumers comprehensive visibility into workloads at reduced storage and processing overheads. The new abstraction, SysFlow, is a compact open data format that lifts the representation of system activities into a flow-centric, object-relational mapping that records how applications interact with their environment, relating processes to file accesses, network activities, and runtime information. The telemetry format supports single-event and volumetric flow representations of process control flows, file interactions, and network communications. Evaluation on enterprise-grade benchmarks shows that SysFlow facilitates deeper introspection into attack kill chains while yielding traces orders of magnitude smaller than current state-of-the-art system telemetry approaches-drastically reducing storage requirements and enabling feature-filled system analytics, process-level provenance tracking, and long-term data archival for cyber threat discovery and forensic analysis on historical data.
引用
收藏
页码:1031 / 1040
页数:10
相关论文
共 50 条
  • [21] A SCALABLE AND OPEN SOURCE LINEAR POSITIONING SYSTEM CONTROLLER
    Medeiros, M. C.
    Fernandes, A. J. A.
    Teixeira, C. A.
    Ruano, M. Graca
    BIODEVICES 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON BIOMEDICAL ELECTRONICS AND DEVICES, 2009, : 410 - 413
  • [22] OPSIS: An Open, Preventive and Scalable Migration Information System
    Pentafronimos, George
    Karantjias, Thanos
    Polemi, Nineta
    NEXT GENERATION SOCIETY: TECHNOLOGICAL AND LEGAL ISSUES, 2010, 26 : 341 - 350
  • [23] Towards Robust and Scalable Power System State Estimation
    Jin, Ming
    Molybog, Igor
    Mohammadi-Ghazi, Reza
    Lavaei, Javad
    2019 IEEE 58TH CONFERENCE ON DECISION AND CONTROL (CDC), 2019, : 3245 - 3252
  • [24] Scalable collective remote attestation towards cloud system
    Song H.-Q.
    You L.-Q.
    Song Y.
    Wang Z.-Y.
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2021, 51 (06): : 2198 - 2206
  • [25] Towards Scalable System-Level Reliability Analysis
    Glass, Michael
    Lukasiewycz, Martin
    Haubelt, Christian
    Teich, Juergen
    PROCEEDINGS OF THE 47TH DESIGN AUTOMATION CONFERENCE, 2010, : 234 - 239
  • [26] Towards Scalable GPU System with Silicon Photonic Chiplet
    Li, Chengeng
    Jiang, Fan
    Chen, Shixi
    Li, Xianbin
    Liu, Jiaqi
    Zhang, Wei
    Xu, Jiang
    2024 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION, DATE, 2024,
  • [27] A scalable delivery system based on RTP JPEG2000 video stream format
    Itakura, E
    Edwards, E
    Futenma, S
    Tomita, N
    Yamane, K
    APPLICATIONS OF DIGITAL IMAGE PROCESSING XXVI, 2003, 5203 : 248 - 254
  • [28] Towards an Open Dependable Operating System
    Ishikawa, Yutaka
    Fujita, Hajime
    Maeda, Toshiyuki
    Matsuda, Motohiko
    Sugaya, Midori
    Sato, Mitsuhisa
    Hanawa, Toshihiro
    Miura, Shinichi
    Boku, Taisuke
    Kinebuchi, Yuki
    Sun, Lei
    Nakajima, Tatsuo
    Nakazawa, Jin
    Tokuda, Hideyuki
    PROCEEDINGS OF THE 12TH IEEE INTERNATIONAL SYMPOSIUM ON OBJECT/COMPONENT/SERVICE-ORIENTED REAL-TIME DISTRIBUTED COMPUTING, 2009, : 20 - +
  • [29] Towards an open grapevine information system
    Adam-Blondon, A-F
    Alaux, M.
    Pommier, C.
    Cantu, D.
    Cheng, Z-M
    Cramer, G. R.
    Davies, C.
    Delrot, S.
    Deluc, L.
    Di Gaspero, G.
    Grimplet, J.
    Fennell, A.
    Londo, J. P.
    Kersey, P.
    Mattivi, F.
    Naithani, S.
    Neveu, P.
    Nikolski, M.
    Pezzotti, M.
    Reisch, B. I.
    Toepfer, R.
    Vivier, M. A.
    Ware, D.
    Quesneville, H.
    HORTICULTURE RESEARCH, 2016, 3
  • [30] PROGRESS TOWARDS OPEN SYSTEM STANDARDS
    TAYLOR, F
    COMPUTER COMMUNICATIONS, 1978, 1 (04) : 210 - 217