2021
DOI: 10.1002/cpe.6561
|View full text |Cite
|
Sign up to set email alerts
|

A fast and accurate threat detection and prevention architecture using stream processing

Abstract: Late detection of security breaches increases the risk of irreparable damages and limits any mitigation attempts. We propose a fast and accurate threat detection and prevention architecture that combines the advantages of real-time streaming with batch processing over a historical database. We create a dataset by capturing both legitimate and malicious traffic and propose two ways of combining packets into flows, one considering a time window and the other analyzing the first few packets of each flow per perio… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
2
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
2
1

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(2 citation statements)
references
References 47 publications
(40 reference statements)
0
2
0
Order By: Relevance
“…Common big data real‐time stream computing systems such as Storm, 4 Spark Streaming 5 and Flink 6 play an important role in many fields, including online system monitoring, 7 mobile sensing data processing 8 and the Internet of Things, 9 financial risk control, 10 recommendation systems, 11 and threat detection 12 …”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…Common big data real‐time stream computing systems such as Storm, 4 Spark Streaming 5 and Flink 6 play an important role in many fields, including online system monitoring, 7 mobile sensing data processing 8 and the Internet of Things, 9 financial risk control, 10 recommendation systems, 11 and threat detection 12 …”
Section: Introductionmentioning
confidence: 99%
“…Common big data real-time stream computing systems such as Storm, 4 Spark Streaming 5 and Flink 6 play an important role in many fields, including online system monitoring, 7 mobile sensing data processing 8 and the Internet of Things, 9 financial risk control, 10 recommendation systems, 11 and threat detection. 12 Storm is a relatively low latency real-time distributed stream processing framework that comes with a default scheduling scheme. Storm uses a pooling method in its allocation process, which often causes load skew.…”
mentioning
confidence: 99%