TARZAN: An Integrated Platform for Security Analysis

Marek Rychlý, Ondřej Ryšavý · Annals of Computer Science and Information Systems · 2017

In this paper, we present the TARZAN platform, an integrated platform for analysis of digital data from security incidents.The platform serves primarily as a middleware between data sources and data processing applications, however, it also provides several supporting services and a runtime environment for the applications.The supporting services, such as a data storage, a resource and application registry, a synchronization service, and a distributed computing platform, are utilized by the TARZAN applications for various security-oriented analyses on the integrated data ranging from an IT security incident detection to inference analyses of data from social networks or cryptocurrency transactions.To cope with a large amount of distributed data, both streamed in real-time and stored, and for the need of a large scale distributed computing, the platform has been designed as a big data processing system ensuring reliable, scalable, and cost-effective solution.The platform is demonstrated on the case of a security analysis of network traffic.

Read the paper · More papers on PaperTik