期刊名称:International Journal of Innovative Research in Computer and Communication Engineering
印刷版ISSN:2320-9798
电子版ISSN:2320-9801
出版年度:2014
卷号:2
期号:10
出版社:S&S Publications
摘要:Enterprises routinely collect terabytes of security-relevant data (for instance, network events, softwareapplication events, and people’s action events) for regulatory compliance and post hoc forensic analysis. Largeenterprises generate an estimated 10 to 100 billion events per day, depending on size. These numbers will only grow asenterprises enable event logging in more sources, hire more employees, deploy more devices, and run more software.Unfortunately, this volume and variety of data quickly become overwhelming. Existing analytical techniques don’twork well at large scales and typically produce so many false positives that their efficacy is undermined. The problembecomes worse as enterprises move to cloud architectures and collect much more data.