Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Evaluation of the data handling pipeline of the ASTRID framework

Contributo in Atti di convegno
Data di Pubblicazione:
2022
Abstract:
Effective attack detection and security analytics rely on the availability of timely and fine-grained information about the evolving context of the protected environment. The data han- dling process entails collection from heterogeneous sources, local aggregation and transformation operations before transmission, and finally collection and delivery to multiple processing engines for analysis and correlation. Many Security Information and Event Management (SIEM) tools work according to the "funnel" principle: gather as much data as possible and then filter it to keep the relevant information. However, this might lead to unacceptable overhead, especially when monitoring containerized environments. As part of our activity in ASTRID, we therefore conducted experimental inves- tigation on resource consumption of the data handling pipeline, starting from embedded agents up to delivery to the Context Broker.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
Elastic stack; containers; monitoring; Kafka
Elenco autori:
Repetto, Matteo
Autori di Ateneo:
REPETTO MATTEO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/444519
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)