Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall
碩士 === 國立中興大學 === 資訊科學與工程學系所 === 101 === With the tremendously improvement of network technologies and the increased popularization of networking, information security has received a significant attention from human beings. Especially, analyzing a huge amount of log data to extract implicit or expli...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2013
|
Online Access: | http://ndltd.ncl.edu.tw/handle/teaw8t |
id |
ndltd-TW-101NCHU5394010 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-101NCHU53940102018-04-10T17:22:46Z http://ndltd.ncl.edu.tw/handle/teaw8t Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall 基於雲端運算架構之安全性資訊和事件管理系統-以網頁應用程式防火牆為例 Tsung-Chih Liu 劉宗治 碩士 國立中興大學 資訊科學與工程學系所 101 With the tremendously improvement of network technologies and the increased popularization of networking, information security has received a significant attention from human beings. Especially, analyzing a huge amount of log data to extract implicit or explicit attacks, so to alert system managers or execute defense procedures has become a major research area. To rapidly and automatically handle the information security issue, many researchers have proposed the Security Informant and Event Management (SIEM) system. Thus, by the SIEM system, we can detect and response immediately when an attack is issued. However, with the rapid growth of amount of digital information, log data is also significantly increased. As a result, using traditional single-computer approach to analyze the large amount of log data becomes impossible. Thus, in this thesis, we utilize the Hadoop-based ecosystem to design and implement a SIEM system on a private cloud. Besides, we use Web Application Firewall as a case study to compare the performance of analyzing the firewall’s logs under different cloud architectures. From the experimental results, Hadoop-based cloud systems can indeed reduce the time of analyzing the log. Therefore, Hadoop-based cloud architecture is suitable to run the system, e.g., SIEM, which requires a significant amount of space and time to store and analyze data respectively. Thus, Hadoop-based cloud can significantly provide IT staff the ability to face and handle the era of Big Data. Hsung-Pin Chang 張軒彬 2013 學位論文 ; thesis 45 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立中興大學 === 資訊科學與工程學系所 === 101 === With the tremendously improvement of network technologies and the increased popularization of networking, information security has received a significant attention from human beings. Especially, analyzing a huge amount of log data to extract implicit or explicit attacks, so to alert system managers or execute defense procedures has become a major research area. To rapidly and automatically handle the information security issue, many researchers have proposed the Security Informant and Event Management (SIEM) system. Thus, by the SIEM system, we can detect and response immediately when an attack is issued.
However, with the rapid growth of amount of digital information, log data is also significantly increased. As a result, using traditional single-computer approach to analyze the large amount of log data becomes impossible. Thus, in this thesis, we utilize the Hadoop-based ecosystem to design and implement a SIEM system on a private cloud. Besides, we use Web Application Firewall as a case study to compare the performance of analyzing the firewall’s logs under different cloud architectures.
From the experimental results, Hadoop-based cloud systems can indeed reduce the time of analyzing the log. Therefore, Hadoop-based cloud architecture is suitable to run the system, e.g., SIEM, which requires a significant amount of space and time to store and analyze data respectively. Thus, Hadoop-based cloud can significantly provide IT staff the ability to face and handle the era of Big Data.
|
author2 |
Hsung-Pin Chang |
author_facet |
Hsung-Pin Chang Tsung-Chih Liu 劉宗治 |
author |
Tsung-Chih Liu 劉宗治 |
spellingShingle |
Tsung-Chih Liu 劉宗治 Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall |
author_sort |
Tsung-Chih Liu |
title |
Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall |
title_short |
Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall |
title_full |
Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall |
title_fullStr |
Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall |
title_full_unstemmed |
Design and Implement of a Hadoop-based SIEM System-A Case Study of Web Application Firewall |
title_sort |
design and implement of a hadoop-based siem system-a case study of web application firewall |
publishDate |
2013 |
url |
http://ndltd.ncl.edu.tw/handle/teaw8t |
work_keys_str_mv |
AT tsungchihliu designandimplementofahadoopbasedsiemsystemacasestudyofwebapplicationfirewall AT liúzōngzhì designandimplementofahadoopbasedsiemsystemacasestudyofwebapplicationfirewall AT tsungchihliu jīyúyúnduānyùnsuànjiàgòuzhīānquánxìngzīxùnhéshìjiànguǎnlǐxìtǒngyǐwǎngyèyīngyòngchéngshìfánghuǒqiángwèilì AT liúzōngzhì jīyúyúnduānyùnsuànjiàgòuzhīānquánxìngzīxùnhéshìjiànguǎnlǐxìtǒngyǐwǎngyèyīngyòngchéngshìfánghuǒqiángwèilì |
_version_ |
1718627990769762304 |