2013 Trend Micro 25th Anniversary Threat Connect : a visualized cyber-threats entity reporting system backed with Hadoop ecosystem Scott Miao, Trend Micro.

Slides:



Advertisements
Similar presentations
Inner Architecture of a Social Networking System Petr Kunc, Jaroslav Škrabálek, Tomáš Pitner.
Advertisements

Abuse Testing Laboratory Management Laboratory Management.
Introducing WatchGuard Dimension. Oceans of Log Data The 3 Dimensions of Big Data Volume –“Log Everything - Storage is Cheap” –Becomes too much data –
Copyright 2012 Trend Micro Inc. Raimund Genes, CTO Innovation In Cloud Security.
Hadoop in the Wild CMSC 491 Hadoop-Based Distributed Computing Spring 2015 Adam Shook.
Observation Pattern Theory Hypothesis What will happen? How can we make it happen? Predictive Analytics Prescriptive Analytics What happened? Why.
Running Hadoop-as-a-Service in the Cloud
1 Advanced Data Structures. 2 Topics Data structures (old) stack, list, array, BST (new) Trees, heaps, union-find, hash tables, spatial, string Algorithm.
Hadoop tutorials. Todays agenda Hadoop Introduction and Architecture Hadoop Distributed File System MapReduce Spark 2.
CS 405G: Introduction to Database Systems 24 NoSQL Reuse some slides of Jennifer Widom Chen Qian University of Kentucky.
Cloud Computing Other Mapreduce issues Keke Chen.
Chapter 2: Business Intelligence Capabilities
Copyright © 2012 Cleversafe, Inc. All rights reserved. 1 Combining the Power of Hadoop with Object-Based Dispersed Storage.
HADOOP ADMIN: Session -2
Hadoop Team: Role of Hadoop in the IDEAL Project ●Jose Cadena ●Chengyuan Wen ●Mengsu Chen CS5604 Spring 2015 Instructor: Dr. Edward Fox.
This presentation was scheduled to be delivered by Brian Mitchell, Lead Architect, Microsoft Big Data COE Follow him Contact him.
Page 1 © Hortonworks Inc – All Rights Reserved Hortonworks Naser Ali UK Building Energy Management Group Hadoop: A Data platform for businesses.
U.S. Department of the Interior U.S. Geological Survey David V. Hill, Information Dynamics, Contractor to USGS/EROS 12/08/2011 Satellite Image Processing.
USING HADOOP & HBASE TO BUILD CONTENT RELEVANCE & PERSONALIZATION Tools to build your big data application Ameya Kanitkar.
Tyson Condie.
Net Optics Confidential and Proprietary Net Optics appTap Intelligent Access and Monitoring Architecture Solutions.
Concept demo System dashboard. Overview Dashboard use case General implementation ideas Use of MULE integration platform Collection Aggregation/Factorization.
SOFTWARE SYSTEMS DEVELOPMENT MAP-REDUCE, Hadoop, HBase.
Building Scalable Web Archives Florent Carpentier, Leïla Medjkoune Internet Memory Foundation IIPC GA, Paris, May 2014.
Introduction to Hadoop 趨勢科技研發實驗室. Copyright Trend Micro Inc. Outline Introduction to Hadoop project HDFS (Hadoop Distributed File System) overview.
The Multiple Uses of HBase Jean-Daniel Cryans, DB Berlin Buzzwords, Germany, June 7 th,
Software Architecture
Appendices: Introduction to Business Intelligence DATE.
HBase A column-centered database 1. Overview An Apache project Influenced by Google’s BigTable Built on Hadoop ▫A distributed file system ▫Supports Map-Reduce.
Hadoop tutorials. Todays agenda Hadoop Introduction and Architecture Hadoop Distributed File System MapReduce Spark Cluster Monitoring 2.
Presented by John Dougherty, Viriton 4/28/2015 Infrastructure and Stack.
Introduction to Hadoop and HDFS
Contents HADOOP INTRODUCTION AND CONCEPTUAL OVERVIEW TERMINOLOGY QUICK TOUR OF CLOUDERA MANAGER.
Modern Databases NoSQL and NewSQL Willem Visser RW334.
Enabling data management in a big data world Craig Soules Garth Goodson Tanya Shastri.
Smart Protection Network Kelvin Liu AVP, Core Tech Development.
Key/Value Stores CMSC 491 Hadoop-Based Distributed Computing Spring 2015 Adam Shook.
Developer TECH REFRESH 15 Junho 2015 #pttechrefres h Understand your end-users and your app with Application Insights.
Introduction to Hbase. Agenda  What is Hbase  About RDBMS  Overview of Hbase  Why Hbase instead of RDBMS  Architecture of Hbase  Hbase interface.
Youngil Kim Awalin Sopan Sonia Ng Zeng.  Introduction  Concept of the Project  System architecture  Implementation – HDFS  Implementation – System.
Apache Hadoop on the Open Cloud David Dobbins Nirmal Ranganathan.
IBM Research ® © 2007 IBM Corporation A Brief Overview of Hadoop Eco-System.
Nov 2006 Google released the paper on BigTable.
NoSQL Systems Motivation. NoSQL: The Name  “SQL” = Traditional relational DBMS  Recognition over past decade or so: Not every data management/analysis.
Big Data Analytics Platforms. Our Team NameApplication Viborov MichaelApache Spark Bordeynik YanivApache Storm Abu Jabal FerasHPCC Oun JosephGoogle BigQuery.
CERN IT Department CH-1211 Genève 23 Switzerland t CERN IT Monitoring and Data Analytics Pedro Andrade (IT-GT) Openlab Workshop on Data Analytics.
Youngil Kim Awalin Sopan Sonia Ng Zeng.  Introduction  System architecture  Implementation – HDFS  Implementation – System Analysis ◦ System Information.
A Validation System for the Complex Event Processing Directives of the ATLAS Shifter Assistant Tool G. Anders (CERN), G. Avolio (CERN), A. Kazarov (PNPI),
Beyond Hadoop The leading open source system for processing big data continues to evolve, but new approaches with added features are on the rise. Ibrahim.
Andy Roberts Data Architect
Microsoft Partner since 2011
Virtual techdays INDIA │ November 2010 SharePoint 2010 – Your one stop shop for all portal requirements Saranya Sriram │ Developer Evangelist, Microsoft.
Microsoft Ignite /28/2017 6:07 PM
Hadoop in the Wild CMSC 491 Hadoop-Based Distributed Computing Spring 2016 Adam Shook.
Data Analytics Challenges Some faults cannot be avoided Decrease the availability for running physics Preventive maintenance is not enough Does not take.
1 Gaurav Kohli Xebia Breaking with DBMS and Dating with Relational Hbase.
Platform as a Service (PaaS)
CS 405G: Introduction to Database Systems
Platform as a Service (PaaS)
Data Analytics and CERN IT Hadoop Service
Hadoop and Analytics at CERN IT
Creating the world’s largest Translation Memory
Modern Databases NoSQL and NewSQL
Enabling Scalable and HA Ingestion and Real-Time Big Data Insights for the Enterprise OCJUG, 2014.
Visual Analytics Sandbox
Near Real Time ETLs with Azure Serverless Architecture
Overview of big data tools
Charles Tappert Seidenberg School of CSIS, Pace University
Big DATA.
UNIT 6 RECENT TRENDS.
Presentation transcript:

2013 Trend Micro 25th Anniversary Threat Connect : a visualized cyber-threats entity reporting system backed with Hadoop ecosystem Scott Miao, Trend

2013 Trend Micro 25th Anniversary Who am I RD, SPN, Trend Micro 3+ years for Hadoop eco system Expertise in

2013 Trend Micro 25th Anniversary Agenda Threat intelligence problem Challenges and Solutions Summary

2013 Trend Micro 25th Anniversary THREAT INTELLIGENCE PROBLEM “I want to quickly get an overview of the incident, including its scope, timeline, and impact.”

2013 Trend Micro 25th Anniversary

2013 Trend Micro 25th Anniversary

2013 Trend Micro 25th Anniversary 7

2013 Trend Micro 25th Anniversary

2013 Trend Micro 25th Anniversary Threat Connect A Web Service for Threat Information Report – RESTful Interface to access – Integrated with TM Deep Discovery products Relevant and Actionable Intelligence

2013 Trend Micro 25th Anniversary

2013 Trend Micro 25th Anniversary IP, domain, URL, filename, process, file hash, Virus detection, registry key, etc. Product 1Product 2Product 3 … Threat Connect Sand- box File Detecti on Threat Web Web Reputa tion Family Write- up TE Virus DB APT KB Most relevant threat report with actionable intelligence on a single portal Process and correlates different data sources

2013 Trend Micro 25th Anniversary CHALLENGES AND SOLUTIONS

2013 Trend Micro 25th Anniversary Storing Real Time Access Pick Your right tool Big Data Moving Process & Correlate Graph Problem

2013 Trend Micro 25th Anniversary MOVING

2013 Trend Micro 25th Anniversary Hadoop Event Logs FBS Feed Back log Service Dear users/services Accumulate small files

2013 Trend Micro 25th Anniversary STORING

2013 Trend Micro 25th Anniversary Cost Easy Process ArchiveHDFS

2013 Trend Micro 25th Anniversary PROCESS & CORRELATE

2013 Trend Micro 25th Anniversary Pig/MR UDFs MRs for special cases Store HDFS Hbase Solr RDB Time Batch Performance

2013 Trend Micro 25th Anniversary REAL TIME ACCESS

2013 Trend Micro 25th Anniversary Real Time Access Free form search Random Access Solr Cloud HBase EX. Sandbox Reports EX. Threat Detection DBs

2013 Trend Micro 25th Anniversary GRAPH MODEL

2013 Trend Micro 25th Anniversary Massive scalable ? Active community ? Analyzable ?

2013 Trend Micro 25th Anniversary We use HBase as a Graph Storage – Google BigTable and PageRank – HBaseCon2012 HBaseCon2012

2013 Trend Micro 25th Anniversary HGraph Schema Design Blueprints API Graph Analysis MRs

2013 Trend Micro 25th Anniversary PICK RIGHT TOOL

2013 Trend Micro 25th Anniversary Pick right tool for right usecases Silver bullet ? No one project fits all One problem may has several choices ecosystem-at-a-glance/

2013 Trend Micro 25th Anniversary SUMMARY

2013 Trend Micro 25th Anniversary Small files Namenode fsimage would explore the memory Too many map tasks to run for a job FBS

2013 Trend Micro 25th Anniversary Store your data anyway Store all the raw data on the HDFS – Break invisible isolation from different data sources Archive your data with deduced easy to use FileFormat – Trenvi, RC file, ORC file

2013 Trend Micro 25th Anniversary Know MR more Even you are the pig developer – Deal with MR issues – Write better pig-latin – Sometimes you can only use MR

2013 Trend Micro 25th Anniversary Know your data & usecases Realtime ? Batch ? Access Pattern ? Therefore, you can pick right tool

2013 Trend Micro 25th Anniversary