A High Throughput Distributed Log Stream Processing System for Network Security Analysis

赵静芬  张鹏  孙永  刘庆云 



Computer-system logs often contain high volumes of interesting, useful information, and are an important data source for network security analysis. In this paper we propose a distributed log stream processing system consisting of three main parts: log collection module, log transmission module and log statistics module. The system uses several open source technologies, not only supports multi-source heterogeneous log collection, but also provides near-real-time online statistics for log stream and offline statistics for massive log. In addition, we adopt a layered architecture in the log collection module, and accomplish a reliable Kafka consumer to get higher scalability as well as reliability. Using log entries generated by the network security platform as data source to do experiment, demonstrates that the proposed system is an effective and practical log stream processing system.




首页
团队介绍
发展历史
组织结构
MESA大事记
新闻中心
通知
组内动态
科研成果
专利
论文
项目
获奖
软著
人才培养
MESA毕业生
MESA在读生
MESA员工
招贤纳士
走进MESA
学长分享
招聘通知
招生宣传
知识库
文章
地址:北京市朝阳区华严北里甲22号楼五层 | 邮编:100029
邮箱:nelist@iie.ac.cn
京ICP备15019404号-1