DocumentCode :
242759
Title :
Runtime Updatable and Dynamic Event Processing Using Embedded ECMAScript Engines
Author :
Azodi, Amir ; Jaeger, David ; Feng Cheng ; Meinel, Christoph
Author_Institution :
Hasso Plattner Inst. (HPI), Univ. of Potsdam, Potsdam, Germany
fYear :
2014
fDate :
28-30 Oct. 2014
Firstpage :
1
Lastpage :
4
Abstract :
Understanding events produced by IT systems is a vital part of effectively managing and maintaining medium and large sized computer networks. As a result, Security Information and Management (SIEM) systems have become an indispensable part of modern networks. One of the main challenges facing SIEM systems is the ability to parse and extract relevant information from the processed events in near real-time. The more diverse the processed events are, the more complicated it becomes to extract the necessary information. Deep event correlation tasks perform very differently over structured data than they do over unstructured data. As an example, a text search for an IP address can take very long, but can return instantly if the IP address is extracted and stored in an appropriate field of its own. Dealing with dozens of different formats using the same event parsing module quickly becomes infeasible. As a result, the parsing of events has largely been outsourced to regular expressions. Although very affective at extracting information from events, they lack sophisticated logic operations. This paper presents a novel method of event processing using an embedded ECMAScript engine to effectively outsource the logic operations needed for deeper event processing.
Keywords :
IP networks; computer network management; computer network security; embedded systems; grammars; information retrieval; text analysis; IP address; IT systems; SIEM systems; computer network maintenance; computer network management; deep event correlation tasks; dynamic event processing; embedded ECMAScript engines; logic operations; regular expressions; relevant information extraction; relevant information parsing; runtime updatable event processing; security information-and-management systems; text search; Data mining; Electronic publishing; Encyclopedias; Engines; Internet; Standards;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
IT Convergence and Security (ICITCS), 2014 International Conference on
Conference_Location :
Beijing
Type :
conf
DOI :
10.1109/ICITCS.2014.7021808
Filename :
7021808
Link To Document :
بازگشت