论文标题

COPA:大数据法医分析系统

CopAS: A Big Data Forensic Analytics System

论文作者

Macak, Martin, Stovcik, Matus, Rebok, Tomas, Ge, Mouzhi, Rossi, Bruno, Buhnova, Barbora

论文摘要

随着我们社会的发展数字化,网络安全已成为大多数组织的关键问题之一。在本文中,我们提出了针对大数据取证分析的系统,使网络运营商可以舒适地分析和关联大量网络数据,以了解有关潜在的恶意和可疑事件的见解。我们证明了COPA的实际用法用于对公开可用的PCAP数据集进行内部攻击检测,并展示了如何使用该系统来检测内部人员在网络中组织过程中生成的大量数据流中隐藏其恶意活动。

With the advancing digitization of our society, network security has become one of the critical concerns for most organizations. In this paper, we present CopAS, a system targeted at Big Data forensics analysis, allowing network operators to comfortably analyze and correlate large amounts of network data to get insights about potentially malicious and suspicious events. We demonstrate the practical usage of CopAS for insider attack detection on a publicly available PCAP dataset and show how the system can be used to detect insiders hiding their malicious activity in the large amounts of data streams generated during the operations of an organization within the network.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源