Hadoop Development - CSC
Hadoop Development - CSC
Hadoop Development - CSC
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Real world example - a Cyber problem (cont’d)<br />
• A first question is where to get the initial list of process IDs from, and there<br />
are two obvious options:<br />
– Wait for the SOC staff to spot SYSCALL events that they are interested in, or<br />
– Make a first pass through the audit logs and for a given day, extract all the SYSCALL<br />
events on that day and then find the owner UIDs for all of them<br />
(Note that since the dataset used for development was quite small, option 2<br />
was practical)<br />
TBSC 2009<br />
11/10/2011 12:53 PM 0725-23_TBSC 2009 27