Fine-Grained Tracking
- f Grid Infections
Ashish Gehani SRI Basim Baig, Salman Mahmood, Dawood Tariq, Fareed Zaffar LUMS
Fine-Grained Tracking of Grid Infections – p. 1/18
Fine-Grained Tracking of Grid Infections Ashish Gehani SRI Basim - - PowerPoint PPT Presentation
Fine-Grained Tracking of Grid Infections Ashish Gehani SRI Basim Baig, Salman Mahmood, Dawood Tariq, Fareed Zaffar LUMS Fine-Grained Tracking of Grid Infections p. 1/18 Introduction Grid semantics Not middleware-specific Distributed
Ashish Gehani SRI Basim Baig, Salman Mahmood, Dawood Tariq, Fareed Zaffar LUMS
Fine-Grained Tracking of Grid Infections – p. 1/18
Fine-Grained Tracking of Grid Infections – p. 2/18
Fine-Grained Tracking of Grid Infections – p. 3/18
Threat Digest Threat Anomalies Anomalies Digest Threat Grid Node Grid Node Grid Node Grid Node Digest Grid Node Grid Node Grid Node Grid Node Anomalies Risk Monitor Grid Node
Edit Layer 0 and 1 as needed Edit Layer 0 and 1 as needed Edit Layer 0 and 1 as needed Edit Layer 0 and 1 as needed Edit Layer 0 and 1 as needed Edit Layer 0 and 1 as needed Edit Layer 0 and 1 as neededFine-Grained Tracking of Grid Infections – p. 4/18
Fine-Grained Tracking of Grid Infections – p. 5/18
Fine-Grained Tracking of Grid Infections – p. 6/18
Fine-Grained Tracking of Grid Infections – p. 7/18
Anomaly Bloom
Filter
Grid Node Risk Monitor Digest
Application Auditing
System Calls User Kernel
Log
Detector Anomaly
Fine-Grained Tracking of Grid Infections – p. 8/18
Fine-Grained Tracking of Grid Infections – p. 9/18
Process File 1 Read File 2 Read close()
close() File 3 Write Process execution Time close()
File 3 File 1 File 2 Owner
Fine-Grained Tracking of Grid Infections – p. 10/18
!"#$
%&"'"()*+,-
.'/0"
1'"2&34*5&
.'/0" 6',7"&&89'"#0" !"#$
&:&72-;<*"="
.'/0" 6',7"&&89'"#0" !"#$ !"#$ !"#$
$%>1*+,-
.'/0"
/"=1+,'"*"=" #11+/7#0/,(*/(/ ?@ABCDEA*FGF3DH4@I;;J*12 &$K,0DEK*"=" ?L?9MN;<*FGF3<F;O<MII*12 &:&72-;<*"="8 7,(P-*/(/ 0#'-"0&*0=0 K,/(7*"="
6',7"&&89'"#0" Fine-Grained Tracking of Grid Infections – p. 11/18
Fine-Grained Tracking of Grid Infections – p. 12/18
Fine-Grained Tracking of Grid Infections – p. 13/18
0.1 1 10 100 1000 10000 100000 1e+06 200000 400000 600000 800000 1e+06 1.2e+06 1.4e+06 Storage Space Used (KB) Number of Events Disk Storage 4000-bit Bloom filter 2000-bit Bloom filter
Fine-Grained Tracking of Grid Infections – p. 14/18
0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 200000 400000 600000 800000 1e+06 1.2e+06 1.4e+06 1.6e+06 False Positives Normalized by Anomalous Sequences Total Number of Events 500-bit Bloom filter 1000-bit Bloom filter 2000-bit Bloom filter 4000-bit Bloom filter
Fine-Grained Tracking of Grid Infections – p. 15/18
0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 200000 400000 600000 800000 1e+006 1.2e+006 1.4e+006 1.6e+006 1.8e+006 False Positives Normalized by Anomalous Sequences Total Number of Events 500-bit Bloom filter 1000-bit Bloom filter 2000-bit Bloom filter 4000-bit Bloom filter
Fine-Grained Tracking of Grid Infections – p. 16/18
500 1000 1500 2000 2500 200 400 600 800 1000 1200 1400 1600 Number of Unique Identifiers Time (minutes) File Identifiers in Normal Data File Identifiers in Attack Data Process Identifiers in Normal and Attack Data
Fine-Grained Tracking of Grid Infections – p. 17/18
Fine-Grained Tracking of Grid Infections – p. 18/18