TUM Logo

SKALD: A Scalable Architecture for Feature Extraction, Multi-User Analysis, and Real-Time Information Sharing

The inability of existing architectures to allow corporations to quickly process information at scale and share knowledge with peers makes it difficult for malware analysis researchers to present a clear picture of criminal activity. Hence, analysis is limited in effectively and accurately identify the full scale of adversaries' activities and develop effective mitigation strategies. In this paper, we present SKALD: a novel architecture which guides the creation of analysis systems to support the research of malicious activities plaguing computer systems. Our design provides the scalability, flexibility, and robustness needed to process current and future volumes of data. We show that our prototype is able to process millions of samples in only few milliseconds per sample with zero critical errors. Additionally, SKALD enables the development of new methodologies for information sharing, enabling analysis across collective knowledge. Consequently, defenders can perform accurate investigations and real-time discovery, while reducing mitigation time and infrastructure cost.

SKALD: A Scalable Architecture for Feature Extraction, Multi-User Analysis, and Real-Time Information Sharing

19th International Conference on Information Security (ISC)

Authors: George Webster, Zachary Hanif, Apostolis Zarras, and Claudia Eckert
Year/month: 2016/9
Booktitle: 19th International Conference on Information Security (ISC)
Publisher: Springer International Publishing
Fulltext: click here

Abstract

The inability of existing architectures to allow corporations to quickly process information at scale and share knowledge with peers makes it difficult for malware analysis researchers to present a clear picture of criminal activity. Hence, analysis is limited in effectively and accurately identify the full scale of adversaries' activities and develop effective mitigation strategies. In this paper, we present SKALD: a novel architecture which guides the creation of analysis systems to support the research of malicious activities plaguing computer systems. Our design provides the scalability, flexibility, and robustness needed to process current and future volumes of data. We show that our prototype is able to process millions of samples in only few milliseconds per sample with zero critical errors. Additionally, SKALD enables the development of new methodologies for information sharing, enabling analysis across collective knowledge. Consequently, defenders can perform accurate investigations and real-time discovery, while reducing mitigation time and infrastructure cost.

Bibtex:

@inproceedings { webster2016skald,
author = { George Webster and Zachary Hanif and Apostolis Zarras and Claudia Eckert},
title = { SKALD: A Scalable Architecture for Feature Extraction, Multi-User Analysis, and Real-Time Information Sharing },
year = { 2016 },
month = { September },
booktitle = { 19th International Conference on Information Security (ISC) },
publisher = { Springer International Publishing },
url = { https://link.springer.com/chapter/10.1007/978-3-319-45871-7_15 },

}