2017
DOI: 10.1109/mcom.2017.1600972
|View full text |Cite
|
Sign up to set email alerts
|

Toward Stream-Based IP Flow Analysis

Abstract: Analyzing IP flows is an essential part of traffic measurement for cyber security. Based on information from IP flows, it is possible to discover the majority of concurrent cyber threats in high-speed, large-scale networks. Some major prevailing challenges for IP flow analysis include, but are not limited to, analysis over a large volume of IP flows, scalability issues, and detecting cyber threats in real time. In this article, we discuss the transformation of present IP flow analysis into a stream-based appro… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
7
0
1

Year Published

2018
2018
2021
2021

Publication Types

Select...
4
2
2

Relationship

2
6

Authors

Journals

citations
Cited by 19 publications
(8 citation statements)
references
References 8 publications
0
7
0
1
Order By: Relevance
“…The prototype serves as a visualization of network parameters. Stream4Flow, however, lacks the intelligence to perform anomaly detection. Hogzilla is an intrusion detection system (IDS) with support for Snort, SFlows, GrayLog, Apache Spark, HBase, and libnDPI, which provides network anomaly detection.…”
Section: Related Workmentioning
confidence: 99%
“…The prototype serves as a visualization of network parameters. Stream4Flow, however, lacks the intelligence to perform anomaly detection. Hogzilla is an intrusion detection system (IDS) with support for Snort, SFlows, GrayLog, Apache Spark, HBase, and libnDPI, which provides network anomaly detection.…”
Section: Related Workmentioning
confidence: 99%
“…Alternative methods, which implement hashing techniques (e.g., sketches) on the network hardware [21], or require enhanced programmability (i.e., beyond OpenFlow) of the forwarding plane [22] [23] [24], still have very limited support on devices, which makes their applicability uncertain. At the same time, solutions based on stream processing [40] [39] can pose a much higher processing burden on local managers, e.g., in the case of large-scale networks with a limited number of LMs, and are unsuitable for many management applications due to the adoption of packet sampling [31].…”
Section: B Monitoring Software-defined Networkmentioning
confidence: 99%
“…To demonstrate a pilot implementation of the framework, we introduce a publicly available prototype Stream4Flow 1 [33]. To highlight the advantages of the framework, we implement NwCSA framework based on IP flow data source.…”
Section: B Prototype Implementationmentioning
confidence: 99%