【updated @ 2014-4-26】


先说一下,“大数据安全分析”是我本人的一个称呼,意即“将大数据分析技术应用于信息安全的技术”,千万别跟“大数据的安全”混淆。“大数据的安全”是指研究大数据本身的安全性,包括针对大数据计算和大数据存储的安全性。我将“大数据安全分析”英文叫做Big Data Security Analysis,或者叫做Big Data based Security Analysis,Gartner则称之为security big data analytics,或者big data for security。

Gartner的分析师Anton Chuvakin认为:95%的用户不会在2014年真正应用大数据安全分析技术,因为其还过于复杂,缺乏商业化的成熟产品支撑,缺少相关的使用技能。(Predicts 2014:Infrastructure Protection)


  • Dearth of COTS [commercial off-the-shelf] big data tools to collect, store and analyze massiveamounts of diverse security data and come to conclusions automatically;

  • Pervasive culture for buying COTS, seeking out-of-the-box features and contents that conflictswith the free-form data exploration approach characteristic of most successful big data projects inother industries;

  • Rapid evolution of big data technologies and their inherent complexities related to distributedcomputing and storage, new data access language and APIs,unstructured data, and so forth;

  • Data exploration, hypothesis testing and modeling approaches needed for making use of big datathat are alien to many security teams that prefer boxed solutions and canned content.



  • “The noise about big data for security has grown deafening in the industry, but the reality lags far, far behind. As many organizations continue to struggle with utilizing traditional security analysis tools, such as security information and event management (SIEM) tools, the expectation that they will magically adopt big data technologies and approaches is simply unrealistic.”

  • “Big data use for security will continue to be populated by the most advanced, mature, Type A organizations for the near future. Security may well be becoming a big data problem, but riding that big data wave will stay difficult and expensive for most organizations.”

  • “Many vendors — new and existing ones — will try to position their technology as big data. However, much of this will remain hype, not reality. “Lean forward” security programs at select large enterprises will still need to build and run their own tools for big data analysis if they choose to embark on this journey.”

  • “Advanced expertise in both information security and data science will be a necessary ingredient in enabling accurate discrimination between malicious and benign activity. “

