"FCCE: Highly scalable distributed Feature Collection and Correlation Engine for low latency big data analytics"
Title | "FCCE: Highly scalable distributed Feature Collection and Correlation Engine for low latency big data analytics" |
Publication Type | Conference Paper |
Year of Publication | 2015 |
Authors | D. L. Schales, X. Hu, J. Jang, R. Sailer, M. P. Stoecklin, T. Wang |
Conference Name | 2015 IEEE 31st International Conference on Data Engineering |
Date Published | April |
Publisher | IEEE |
ISBN Number | 978-1-4799-7964-6 |
Accession Number | 15180717 |
Keywords | advanced persistent threat infection detection, Big Data, computer security, Correlation, cyber security domain, data mining, Distributed databases, FCCE, feature extraction, feature selection, fluxing domain name detection, geographically distributed large data sets, highly scalable distributed feature collection and correlation engine analysis engine, IP networks, low latency Big Data analytics, low latency query responses, production network query, pubcrawl170101, query processing, Real-time Systems, security analytics, security intelligence, security of data, time windows |
Abstract | In this paper, we present the design, architecture, and implementation of a novel analysis engine, called Feature Collection and Correlation Engine (FCCE), that finds correlations across a diverse set of data types spanning over large time windows with very small latency and with minimal access to raw data. FCCE scales well to collecting, extracting, and querying features from geographically distributed large data sets. FCCE has been deployed in a large production network with over 450,000 workstations for 3 years, ingesting more than 2 billion events per day and providing low latency query responses for various analytics. We explore two security analytics use cases to demonstrate how we utilize the deployment of FCCE on large diverse data sets in the cyber security domain: 1) detecting fluxing domain names of potential botnet activity and identifying all the devices in the production network querying these names, and 2) detecting advanced persistent threat infection. Both evaluation results and our experience with real-world applications show that FCCE yields superior performance over existing approaches, and excels in the challenging cyber security domain by correlating multiple features and deriving security intelligence. |
URL | http://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=7113379&isnumber=7113253 |
DOI | 10.1109/ICDE.2015.7113379 |
Citation Key | 7113379 |
- highly scalable distributed feature collection and correlation engine analysis engine
- time windows
- security of data
- security intelligence
- security analytics
- real-time systems
- query processing
- pubcrawl170101
- production network query
- low latency query responses
- low latency Big Data analytics
- IP networks
- advanced persistent threat infection detection
- geographically distributed large data sets
- fluxing domain name detection
- Feature Selection
- feature extraction
- FCCE
- Distributed databases
- Data mining
- cyber security domain
- Correlation
- computer security
- Big Data