List of Topics:
Location Research Breakthrough Possible @S-Logix pro@slogix.in

Office Address

Social List

A Scalable Architecture Exploiting Elastic Stack and Meta Ensemble of Classifiers for Profiling User Behaviour - 2022

a-scalable-architecture-exploiting-elastic-stack-and-meta-ensemble-of-classifiers-for-profiling-user-behaviour.jpg

A Scalable Architecture Exploiting Elastic Stack and Meta Ensemble of Classifiers for Profiling User Behaviour | S-Logix

Research Area:  Machine Learning

Abstract:

Large user and application logs are generated and stored by many organisations at a rate that makes it really hard to analyse, especially in real-time. In particular, in the field of cybersecurity, it is of great interest to analyse fast user logs, coming from different and heterogeneous sources, in order to prevent data breach issues caused by user behaviour. In addition to these problems, often part of the data or some entire sources are missing. To overcome these issues, we propose a framework based on the Elastic Stack (ELK) to process and store log data coming from different users and applications to generate an ensemble of classifiers, in order to classify the user behaviour, and eventually to detect anomalies. The system exploits the scalable architecture of ELK by running on top of a Kubernetes platform and adopts a distributed evolutionary algorithm for classifying the users, on the basis of their digital footprints, derived by many sources of data. Preliminary experiments show that the system is effective in classifying the behaviour of the different users and that this can be considered as an auxiliary task for detecting anomalies in their behaviour, by helping to reduce the number of false alarms.

Keywords:  
Distributed databases
Evolutionary computation
Data breach
Real-time systems
Task analysis
Computer security

Author(s) Name:  Gianluigi Folino,Carla Otranto Godano,Francesco Sergi

Journal name:  

Conferrence name:  2022 30th Euromicro International Conference on Parallel, Distributed and Network-based Processing

Publisher name:  IEEE

DOI:  10.1109/PDP55904.2022.00037

Volume Information: