Visible to the public Towards Distributed Threat Intelligence in Real-Time

TitleTowards Distributed Threat Intelligence in Real-Time
Publication TypeConference Paper
Year of Publication2017
AuthorsMeyer, Philipp, Hiesgen, Raphael, Schmidt, Thomas C., Nawrocki, Marcin, Wählisch, Matthias
Conference NameProceedings of the SIGCOMM Posters and Demos
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5057-0
KeywordsHuman Behavior, Internet security, Metrics, network forensic, pubcrawl, resilience, Resiliency, threat detection, threat mitigation
Abstract

In this demo, we address the problem of detecting anomalies on the Internet backbone in near real-time. Many of today's incidents may only become visible from inspecting multiple data sources and by considering multiple vantage points simultaneously. We present a setup based on the distributed forensic platform VAST that was extended to import various data streams from passive measurements and incident reporting at multiple locations, and perform an effective correlation analysis shortly after the data becomes exposed to our queries.

URLhttps://dl.acm.org/citation.cfm?doid=3123878.3131992
DOI10.1145/3123878.3131992
Citation Keymeyer_towards_2017