Threat Analysis and Identification using MapReduce Hadoop Platform |
||||
|
|
||||
|
||||
BibTeX: |
||||
|
@article{IJIRSTV1I7074, |
||||
Abstract: |
||||
|
The area of security forensic has become important. More advance security attacks are growing day by day and the complexity of analyzing or identifying those persistent malicious program has grown. These malicious programs reside in our system as an innocent program and behave like normal program and are sometimes untraceable by the advance threat protection software such as antiviruses, but in the background either they are stealing data or they are creating some destructive programs. These threats can only be found out by proper analysis of the system's activity. Most system programs that reside in our computer system log each and every activity in the log files. Analyzing those log file help us in identifying the possible suspicious activity. The system presented in this paper tries to solve this problem by analyzing those log file using the most powerful processing framework "Hadoop". |
||||
Keywords: |
||||
|
Event Correlation, Hadoop, Log File Analysis, Mapreduce, Threat Detection. |
||||



