Back to results

University of Illinois at Urbana-Champaign

Scalable data analytics pipeline for real-time attack detection: design, validation, and deployment in a honeypot environment

Abstract

dc:description

This work explores a scalable data analytics pipeline for real-time attack detection through the use of customized honeypots at the National Center for Supercomputing Applications (NCSA). Attack detection tools are common and are constantly getting improved, but validating these tools is challenging. One must automate how to identify what data is essential to detecting the attack, extract this data from multiple different monitors, and send this data to the attack detection tool. On top of this, one must be able to efficiently scale with an ever-increasing amount of data, while also having the ability to extend to new monitors. This requires an infrastructure that is non-trivial to create or to deploy. In this work, we present a generalized architecture that aims for a real- time, scalable, and extensible pipeline that can be deployed in diverse in- frastructures to validate arbitrary attack detection tools. To demonstrate our architecture, we will show an example deployment of our pipeline using completely open-sourced tools. Our example deployment uses as its sources: 1) a customized honeypot environment at NCSA, and 2) customized attack scripts written to follow the skeleton of canonical credential-stealing attacks. To extract useful information, we have deployed network and host-based monitoring tools such as Bro and OSSEC. We have also built an attack de- tection tool named AttackTagger that we will use as our front-end detection engine.

Degree

thesis:*
Name thesis:degree_name
M.S.
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Electrical & Computer Engineering
Grantor
University of Illinois at Urbana-Champaign
Year dc:date
2016

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Badger, Eric C
Contributors dc:contributor
  • Iyer, Ravishankar K.
  • Kalbarczyk, Zbigniew T

Subjects

dc:subject × 1

Rights

dc:rights
Statement dc:rights
  • Copyright 2015 Eric Badger
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier
http://hdl.handle.net/2142/89057
OAI identifier oai:identifier
oai:www.ideals.illinois.edu:2142/89057

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Badger, Eric C. Scalable data analytics pipeline for real-time attack detection: design, validation, and deployment in a honeypot environment. Thesis thesis, University of Illinois at Urbana-Champaign, 2016. http://hdl.handle.net/2142/89057