With the advancing digitization of our society, network security has become one of the critical concerns for most organizations. In this paper, we present CopAS, a system targeted at Big Data forensics analysis, allowing network operators to comfortably analyze and correlate large amounts of network data to get insights about potentially malicious and suspicious events. We demonstrate the practical usage of CopAS for insider attack detection on a publicly available PCAP dataset and show how the system can be used to detect insiders hiding their malicious activity in the large amounts of data streams generated during the operations of an organization within the network.
翻译:随着社会数字化进程的推进,网络安全已成为大多数组织关注的关键问题之一。本文介绍了一种面向大数据取证分析的系统CopAS,该系统能够使网络运营人员便捷地分析并关联大量网络数据,从而洞察潜在恶意与可疑事件。我们通过公开可用的PCAP数据集,展示了CopAS在内部攻击检测中的实际应用,并说明了如何利用该系统检测那些将恶意活动隐藏于组织网络运行产生的大量数据流中的内部人员。