Главная
Study mode:
on
1
Introduction
2
Who am I
3
What is event correlation
4
What is Giles
5
Complex predicates
6
Holistic engines
7
Dirt
8
Giles
9
Facts
10
Fields
11
Facts are data
12
Restoring state
13
Example
14
Engineering wins
15
Giles guarantee
16
Live demo
17
Advantages
18
Performance
19
Reedy
20
Summary
Description:
Explore event correlation in information security and forensics through this Black Hat conference talk. Delve into the challenges of log analysis, behavior detection, record linkage, and expert systems. Learn about Giles, a compiler that creates event correlation engines, and discover how its output can be used to create SQL databases that function as fully-fledged event correlation engines. Understand the advantages of this approach, including the ability to deploy event correlation engines anywhere a database can be placed and access them using any programming language. Follow along with a live demo and gain insights into the performance benefits and engineering wins of this innovative approach to event correlation.

Taking Event Correlation With You

Black Hat
Add to list