2020
Cyber Situation Awareness via IP Flow Monitoring
JIRSÍK, Tomáš and Pavel ČELEDABasic information
Original name
Cyber Situation Awareness via IP Flow Monitoring
Authors
JIRSÍK, Tomáš (203 Czech Republic, guarantor, belonging to the institution) and Pavel ČELEDA (203 Czech Republic, belonging to the institution)
Edition
Hungary, 2020 IEEE/IFIP Network Operations and Management Symposium (NOMS 2020), p. 1-6, 6 pp. 2020
Publisher
IEEE Xplore Digital Library
Other information
Language
English
Type of outcome
Proceedings paper
Country of publisher
Czech Republic
Confidentiality degree
is not subject to a state or trade secret
Publication form
electronic version available online
References:
RIV identification code
RIV/00216224:14610/20:00115562
Organization
Ústav výpočetní techniky – Repository – Repository
ISBN
978-1-7281-4973-8
ISSN
UT WoS
000716920500055
Keywords in English
cyber situation awareness; IP flow; monitoring; network; real-time; host identification
Links
EF16_019/0000822, research and development project.
Changed: 31/3/2023 04:06, RNDr. Daniel Jakubík
Abstract
V originále
Cyber situation awareness has been recognized as a vital requirement for effective cyber defense. Cyber situation awareness allows cybersecurity operators to identify, understand, and anticipate incoming threats. Achieving and maintaining the cyber situation awareness is a challenging task given the continuous evolution of the computer networks, increasing volume and speeds of the data in a network, and rising number of threats to network security. Our work contributes to the continuous evolution of cyber situation awareness by the research of novel approaches to the perception and comprehension of a computer network. We concentrate our research efforts on the domain of IP flow network monitoring. We propose improvements to the IP flow monitoring techniques that enable the enhanced perception of a computer network. Further, we conduct detailed analyses of network traffic, which allows for an in-depth understanding of host behavior in a computer network. Last but not least, we propose a novel approach to IP flow network monitoring that enables real-time cyber situation awareness.