{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/a-security-monitoring-framework-for","title":"A Security Monitoring Framework For Virtualization Based HEP Infrastructures","arxiv_id":"1704.04782","date":"2017-04-16","proceeding":null,"authors":["A. Gomez Ramirez","M. Martinez Pedreira","C. Grigoras","L. Betev","C. Lara","U. Kebschull for the ALICE Collaboration"],"abstract":"High Energy Physics (HEP) distributed computing infrastructures require\nautomatic tools to monitor, analyze and react to potential security incidents.\nThese tools should collect and inspect data such as resource consumption, logs\nand sequence of system calls for detecting anomalies that indicate the presence\nof a malicious agent. They should also be able to perform automated reactions\nto attacks without administrator intervention. We describe a novel framework\nthat accomplishes these requirements, with a proof of concept implementation\nfor the ALICE experiment at CERN. We show how we achieve a fully virtualized\nenvironment that improves the security by isolating services and Jobs without a\nsignificant performance impact. We also describe a collected dataset for\nMachine Learning based Intrusion Prevention and Detection Systems on Grid\ncomputing. This dataset is composed of resource consumption measurements (such\nas CPU, RAM and network traffic), logfiles from operating system services, and\nsystem call data collected from production Jobs running in an ALICE Grid test\nsite and a big set of malware. This malware was collected from security\nresearch sites. Based on this dataset, we will proceed to develop Machine\nLearning algorithms able to detect malicious Jobs.","url_abs":"http://arxiv.org/abs/1704.04782v1","url_pdf":"http://arxiv.org/pdf/1704.04782v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"a-security-monitoring-framework-for","repo_url":"https://github.com/kuronosec/arhuaco","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":null,"task_name":"CPU"},{"task_slug":"distributed-computing","task_name":"Distributed Computing"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}