Download presentation
Presentation is loading. Please wait.
Published byCornelius Oliver Modified over 9 years ago
1
COMP 415, Spring 2008
2
T ABLE OF C ONTENTS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo
3
D ATA P ARSING 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo
4
D ATA P ARSING Transform raw data 84673912-13-09175000AABLog String:
5
D ATA P ARSING Transform raw data Log Parser or API JPM Service Parser Atropos API API Call To Correlation Engine Log FileAPI Call
6
M ATCHES 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo
7
M ATCHES Single correlation point One or more parameters Match OneMatch Two
8
C ORRELATION S TRATEGIES 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo
9
C ORRELATION S TRATEGIES One or more matches Strength is “sum” of matches Multiple strategies
10
C ORRELATION R ULESETS 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo
11
C ORRELATION R ULESETS One link in association graph Matches Strategies Data structures Corollary: Parsing Rules
12
C ONCLUSION & D EMO 1. Data Parsing 2. Matches 3. Correlation Strategies 4. Correlation Rulesets 5. Conclusion & Demo
13
C ONCLUSION - SUMMARY Matches link messages Strategies compose Correlation Rulesets map to network
14
C ONCLUSION - QUESTIONS How efficient is matching? How to match w/o rules? How to match substrings?
15
Thank You For Listening!
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.