SKALD: A Scalable Architecture for Feature Extraction, Multi-user Analysis, and Real-Time Information Sharing

SKALD: A Scalable Architecture for Feature Extraction, Multi-user Analysis, and Real-Time Information Sharing
复制标题

SKALD:用于特征提取、多用户分析和实时信息共享的可扩展架构

DOI:
10.1007/978-3-319-45871-7_15
复制
发表时间:
2016
期刊:
2008 International Conference on Autonomic Computing
影响因子:
--
通讯作者:
C. Eckert
C. Eckert
中科院分区:
--
文献类型:
--
作者:
George D. Webster;Zachary D. Hanif;Andre L. P. Ludwig;Tamas K. Lengyel;Apostolis Zarras;C. Eckert

文献摘要

被引文献

相似文献

现有架构无法让企业快速处理大规模信息并与同行共享知识,这使得恶意软件分析研究人员很难清楚地了解犯罪活动。因此,分析在有效和准确地识别对手活动的全面规模和制定有效的缓解策略方面受到限制。在本文中,我们提出了Skald:一个新的架构,指导分析系统的创建,以支持研究恶意活动的计算机系统。我们的设计提供了处理当前和未来大量数据所需的可扩展性、灵活性和健壮性。我们表明,我们的原型是能够处理数百万个样本,每个样本只有几毫秒,零临界误差。此外,Skald还可以开发新的信息共享方法,从而实现对集体知识的分析。因此,防御者可以执行准确的调查和实时发现,同时减少缓解时间和基础设施成本。
The inability of existing architectures to allow corporations to quickly process information at scale and share knowledge with peers makes it difficult for malware analysis researchers to present a clear picture of criminal activity. Hence, analysis is limited in effectively and accurately identify the full scale of adversaries’ activities and develop effective mitigation strategies. In this paper, we present Skald: a novel architecture which guides the creation of analysis systems to support the research of malicious activities plaguing computer systems. Our design provides the scalability, flexibility, and robustness needed to process current and future volumes of data. We show that our prototype is able to process millions of samples in only few milliseconds per sample with zero critical errors. Additionally, Skald enables the development of new methodologies for information sharing, enabling analysis across collective knowledge. Consequently, defenders can perform accurate investigations and real-time discovery, while reducing mitigation time and infrastructure cost.