D 2021

Stream-Based IP Flow Analysis

ČERMÁK, Milan a Pavel ČELEDA

Základní údaje

Originální název

Stream-Based IP Flow Analysis

Autoři

ČERMÁK, Milan a Pavel ČELEDA

Vydání

Bordeaux, France, IFIP/IEEE International Symposium on Integrated Network Management, IM 2021, od s. 736-741, 6 s. 2021

Nakladatel

IFIP Open Digital Library

Další údaje

Jazyk

angličtina

Typ výsledku

Stať ve sborníku

Stát vydavatele

Spojené státy

Utajení

není předmětem státního či obchodního tajemství

Forma vydání

elektronická verze "online"

Odkazy

Organizace

Ústav výpočetní techniky – Masarykova univerzita – Repozitář

ISBN

978-3-903176-32-4

UT WoS

000696801700108

EID Scopus

2-s2.0-85113673996

Klíčová slova anglicky

Stream Processing; IP Flow; Stream4Flow

Návaznosti

EF16_019/0000822, projekt VaV.
Změněno: 18. 4. 2022 02:36, RNDr. Daniel Jakubík

Anotace

V originále

As the complexity of Internet services, transmission speed, and data volume increases, current IP flow monitoring and analysis approaches cease to be sufficient, especially within high-speed and large-scale networks. Although IP flows consist only of selected network traffic features, their processing faces high computational demands, analysis delays, and large storage requirements. To address these challenges, we propose to improve the IP flow monitoring workflow by stream-based collection and analysis of IP flows utilizing a distributed data stream processing. This approach requires changing the paradigm of IP flow data monitoring and analysis, which is the main goal of our research. We analyze distributed stream processing systems, for which we design a novel performance benchmark to determine their suitability for stream-based processing of IP flow data. We define a stream-based workflow of IP flow collection and analysis based on the benchmark results, which we also implement as a publicly available and open-source framework Stream4Flow. Furthermore, we propose new analytical methods that leverage the stream-based IP flow data processing approach and extend network monitoring and threat detection capabilities.

Přiložené soubory