13.11.2012 Views

Hadoop Development - CSC

Hadoop Development - CSC

Hadoop Development - CSC

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Real world example - a Cyber problem (cont’d)<br />

• A first question is where to get the initial list of process IDs from, and there<br />

are two obvious options:<br />

– Wait for the SOC staff to spot SYSCALL events that they are interested in, or<br />

– Make a first pass through the audit logs and for a given day, extract all the SYSCALL<br />

events on that day and then find the owner UIDs for all of them<br />

(Note that since the dataset used for development was quite small, option 2<br />

was practical)<br />

TBSC 2009<br />

11/10/2011 12:53 PM 0725-23_TBSC 2009 27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!