Towards an Open Format for Scalable System Telemetry

被引:3
|
作者
Taylor, Teryl [1 ]
Araujo, Frederico [1 ]
Shu, Xiaokui [1 ]
机构
[1] IBM Res, Yorktown Hts, NY 10598 USA
关键词
telemetry; open standard; data representation; system monitoring; threat detection;
D O I
10.1109/BigData50022.2020.9378294
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A data representation for system behavior telemetry for scalable big data security analytics is presented, affording telemetry consumers comprehensive visibility into workloads at reduced storage and processing overheads. The new abstraction, SysFlow, is a compact open data format that lifts the representation of system activities into a flow-centric, object-relational mapping that records how applications interact with their environment, relating processes to file accesses, network activities, and runtime information. The telemetry format supports single-event and volumetric flow representations of process control flows, file interactions, and network communications. Evaluation on enterprise-grade benchmarks shows that SysFlow facilitates deeper introspection into attack kill chains while yielding traces orders of magnitude smaller than current state-of-the-art system telemetry approaches-drastically reducing storage requirements and enabling feature-filled system analytics, process-level provenance tracking, and long-term data archival for cyber threat discovery and forensic analysis on historical data.
引用
收藏
页码:1031 / 1040
页数:10
相关论文
共 50 条
  • [41] Towards Scalable Kernel-Based Regularized System Identification
    Chen, Lujing
    Chen, Tianshi
    Detha, Utkarsh
    Andersen, Martin S.
    2023 62ND IEEE CONFERENCE ON DECISION AND CONTROL, CDC, 2023, : 1498 - 1504
  • [42] Flexible Bandwidth Arbitrary Modulation Format, Coherent Optical Transmission System Scalable to Terahertz BW
    Geisler, David J.
    Fontaine, Nicolas K.
    Scott, Ryan P.
    Paraschis, Loukas
    Gerstel, Ori
    Yoo, S. J. B.
    2011 37TH EUROPEAN CONFERENCE AND EXHIBITION ON OPTICAL COMMUNICATIONS (ECOC 2011), 2011,
  • [43] Towards an argument interchange format
    Chesnevar, Carlos
    McGinnis, Jarred
    Modgil, Sanjay
    Rahwan, Iyad
    Reed, Chris
    Simari, Guillermo
    South, Matthew
    Vreeswijk, Gerard
    Willmott, Steven
    KNOWLEDGE ENGINEERING REVIEW, 2006, 21 (04): : 293 - 316
  • [44] Advanced Forensic Format: An open extensible format for disk imaging
    Garfinkel, S.
    Malan, D.
    Dubec, K.
    Stevens, C.
    Pham, C.
    Advances in Digital Forensics II, 2006, 222 : 13 - 27
  • [45] Towards Cross-Layer Telemetry
    Iurman, Justin
    Brockners, Frank
    Donnet, Benoit
    PROCEEDINGS OF THE 2021 APPLIED NETWORKING RESEARCH WORKSHOP, ANRW 2021, 2021, : 15 - 21
  • [46] Towards an Open-Domain Dialog System
    Gao, Jianfeng
    PROCEEDINGS OF THE 2019 ACM SIGIR INTERNATIONAL CONFERENCE ON THEORY OF INFORMATION RETRIEVAL (ICTIR'19), 2019, : 1 - 1
  • [47] NetVision: Towards Network Telemetry as a Service
    Liu, Zhengzheng
    Bi, Jun
    Zhou, Yu
    Wang, Yangyang
    Lin, Yunsenxiao
    2018 IEEE 26TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2018, : 247 - 248
  • [48] Towards a lightweight distributed telemetry for microservices
    Otero, Manuel
    Maria Garcia, Jose
    Fernandez, Pablo
    2024 IEEE 44TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS, ICDCS 2024, 2024, : 75 - 82
  • [49] Towards an eBPF plus XDP based Framework for Open, Programmable and Scalable NextG RANs
    Dayalan, Udhaya Kumar
    Wu, Ziyan
    Gautam, Gaurav
    Tian, Feng
    Zhang, Zhi-Li
    2023 IEEE FUTURE NETWORKS WORLD FORUM, FNWF, 2024,
  • [50] Multi-layer scalable LPC audio format
    Jbira, A
    Kondoz, A
    ISCAS 2000: IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS - PROCEEDINGS, VOL III: EMERGING TECHNOLOGIES FOR THE 21ST CENTURY, 2000, : 209 - 212