Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Taking Event Correlation With You

Black Hat via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore event correlation in information security and forensics through this Black Hat conference talk. Delve into the challenges of log analysis, behavior detection, record linkage, and expert systems. Learn about Giles, a compiler that creates event correlation engines, and discover how its output can be used to create SQL databases that function as fully-fledged event correlation engines. Understand the advantages of this approach, including the ability to deploy event correlation engines anywhere a database can be placed and access them using any programming language. Follow along with a live demo and gain insights into the performance benefits and engineering wins of this innovative approach to event correlation.

Syllabus

Introduction
Who am I
What is event correlation
What is Giles
Complex predicates
Holistic engines
Dirt
Giles
Facts
Fields
Facts are data
Restoring state
Example
Engineering wins
Giles guarantee
Live demo
Advantages
Performance
Reedy
Summary

Taught by

Black Hat

Reviews

Start your review of Taking Event Correlation With You

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.