The document presents a big data-based security analytics (BDSA) approach for protecting virtualized infrastructures in cloud computing against cyber attacks. It describes the method of collecting network and user application logs, using graph-based event correlation and a two-step machine learning process to detect attacks in real-time. Experimental results indicate that this approach effectively identifies advanced attacks with minimal performance overhead.