Title
MATATABI: Multi-layer Threat Analysis Platform with Hadoop
Abstract
Threat detection and analysis are indispensable processes in today's cyberspace, but current state of the art threat detection is still limited to specific aspects of modern malicious activities due to the lack of information to analyze. By measuring and collecting various types of data, from traffic information to human behavior, at different vantage points for a long duration, the viewpoint seems to be helpful to deeply inspect threats, but faces scalability issues as the amount of collected data grows, since more computational resources are required for the analysis. In this paper, we report our experience from operating the Hadoop platform, called MATATABI, for threat detections, and present the micro-benchmarks with four different backends of data processing in typical use cases such as log data and packet trace analysis. The benchmarks demonstrate the advantages of distributed computation in terms of performance. Our extensive use cases of analysis modules showcase the potential benefit of deploying our threat analysis platform.
Year
DOI
Venue
2014
10.1109/BADGERS.2014.12
2014 Third International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS)
Keywords
DocType
ISBN
MATATABI,multilayer threat analysis platform,threat detection,cyberspace,traffic information,human behavior,scalability issues,Hadoop platform,micro-benchmarks,data processing,distributed computation
Conference
978-1-4799-8308-7
Citations 
PageRank 
References 
1
0.38
0
Authors
4
Name
Order
Citations
PageRank
Hajime Tazaki111.05
Kazuya Okada212.74
Yuji Sekiya3259.50
Youki Kadobayashi446365.10