TY - GEN
T1 - ENTRADA
T2 - 2016 APWG Symposium on Electronic Crime Research, eCrime 2016
AU - Wullink, Maarten
AU - Muller, Moritz
AU - Davids, Marco
AU - Moura, Giovane C.M.
AU - Hesselman, Cristian
N1 - Publisher Copyright:
© 2016 IEEE.
PY - 2016/6/8
Y1 - 2016/6/8
N2 - DNS operators, TLD registries, hosting providers, and other Internet operators are frequently faced with the same question: how to draw insights and knowledge from their respective network traffic data in order to improve their services, security, and operations? "Big data" processing solutions play a major role as an enabling platform in this sense, especially with the increasing growth of the volume of Internet traffic. With this in mind, we have developed and presented in a previous work ENTRADA, an open-source high-performance Hadoop-based data streaming warehouse designed to both ingest continuous streams of data and deliver interactive response times over large datasets, even in a small cluster. Whereas in the previous study we focused on the architecture and performance evaluation, in this paper we present a series of use cases and applications that cover phishing, botnets, email security, and visualizations. These applications can be directly used by DNS operators, TLD registries, and researchers to quickly analyze their network data and improve their services, security, and operations.
AB - DNS operators, TLD registries, hosting providers, and other Internet operators are frequently faced with the same question: how to draw insights and knowledge from their respective network traffic data in order to improve their services, security, and operations? "Big data" processing solutions play a major role as an enabling platform in this sense, especially with the increasing growth of the volume of Internet traffic. With this in mind, we have developed and presented in a previous work ENTRADA, an open-source high-performance Hadoop-based data streaming warehouse designed to both ingest continuous streams of data and deliver interactive response times over large datasets, even in a small cluster. Whereas in the previous study we focused on the architecture and performance evaluation, in this paper we present a series of use cases and applications that cover phishing, botnets, email security, and visualizations. These applications can be directly used by DNS operators, TLD registries, and researchers to quickly analyze their network data and improve their services, security, and operations.
KW - n/a OA procedure
UR - https://www.scopus.com/pages/publications/84977279478
U2 - 10.1109/ECRIME.2016.7487939
DO - 10.1109/ECRIME.2016.7487939
M3 - Conference contribution
AN - SCOPUS:84977279478
T3 - eCrime Researchers Summit, eCrime
SP - 14
EP - 24
BT - Proceedings of the 2016 APWG Symposium on Electronic Crime Research, eCrime 2016
PB - IEEE
Y2 - 1 June 2016 through 3 June 2016
ER -