2021
Stream-Based IP Flow Analysis
ČERMÁK, Milan a Pavel ČELEDAZákladní údaje
Originální název
Stream-Based IP Flow Analysis
Autoři
ČERMÁK, Milan a Pavel ČELEDA
Vydání
Bordeaux, France, IFIP/IEEE International Symposium on Integrated Network Management, IM 2021, od s. 736-741, 6 s. 2021
Nakladatel
IFIP Open Digital Library
Další údaje
Jazyk
angličtina
Typ výsledku
Stať ve sborníku
Stát vydavatele
Spojené státy
Utajení
není předmětem státního či obchodního tajemství
Forma vydání
elektronická verze "online"
Odkazy
Organizace
Ústav výpočetní techniky – Masarykova univerzita – Repozitář
ISBN
978-3-903176-32-4
UT WoS
000696801700108
EID Scopus
2-s2.0-85113673996
Klíčová slova anglicky
Stream Processing; IP Flow; Stream4Flow
Návaznosti
EF16_019/0000822, projekt VaV.
Změněno: 18. 4. 2022 02:36, RNDr. Daniel Jakubík
Anotace
V originále
As the complexity of Internet services, transmission speed, and data volume increases, current IP flow monitoring and analysis approaches cease to be sufficient, especially within high-speed and large-scale networks. Although IP flows consist only of selected network traffic features, their processing faces high computational demands, analysis delays, and large storage requirements. To address these challenges, we propose to improve the IP flow monitoring workflow by stream-based collection and analysis of IP flows utilizing a distributed data stream processing. This approach requires changing the paradigm of IP flow data monitoring and analysis, which is the main goal of our research. We analyze distributed stream processing systems, for which we design a novel performance benchmark to determine their suitability for stream-based processing of IP flow data. We define a stream-based workflow of IP flow collection and analysis based on the benchmark results, which we also implement as a publicly available and open-source framework Stream4Flow. Furthermore, we propose new analytical methods that leverage the stream-based IP flow data processing approach and extend network monitoring and threat detection capabilities.