Presentation is loading. Please wait.

Presentation is loading. Please wait.

COMP 415, Spring 2008. T ABLE OF C ONTENTS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo.

Similar presentations


Presentation on theme: "COMP 415, Spring 2008. T ABLE OF C ONTENTS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo."— Presentation transcript:

1 COMP 415, Spring 2008

2 T ABLE OF C ONTENTS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo

3 D ATA P ARSING 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo

4 D ATA P ARSING Transform raw data 84673912-13-09175000AABLog String:

5 D ATA P ARSING Transform raw data Log Parser or API JPM Service Parser Atropos API API Call To Correlation Engine Log FileAPI Call

6 M ATCHES 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo

7 M ATCHES Single correlation point One or more parameters Match OneMatch Two

8 C ORRELATION S TRATEGIES 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo

9 C ORRELATION S TRATEGIES One or more matches Strength is “sum” of matches Multiple strategies

10 C ORRELATION R ULESETS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo

11 C ORRELATION R ULESETS One link in association graph Matches Strategies Data structures Corollary: Parsing Rules

12 C ONCLUSION & D EMO 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo

13 C ONCLUSION - SUMMARY Matches link messages Strategies compose Correlation Rulesets map to network

14 C ONCLUSION - QUESTIONS How efficient is matching? How to match w/o rules? How to match substrings?

15 Thank You For Listening!


Download ppt "COMP 415, Spring 2008. T ABLE OF C ONTENTS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo."

Similar presentations


Ads by Google