A NetFlow based flow analysis and monitoring system in enterprise networks
نویسندگان
چکیده
In this paper, a flow analysis and monitoring system based on NetFlow is introduced. The system is built on a Browser– Server framework, aimed at enterprise networks. Data collection and display are separated into two modules, which makes the system clearly demarcated and easy to deploy. The data collection module receives and analyzes NetFlow-exported packets and inserts per flow record information into the Oracle database. The display module acts as a J2EE web server, fetches real-time or history traffic information from the database and shows it to web users. In addition to the above-mentioned functions, the most important part of the system is an IDS. A real-time anomalous traffic monitoring module with a stable matching pattern algorithm and two traffic statistic based intrusion detection algorithms – one algorithm is based on variance similarity while the other is based on Euclidean distance – are embedded in the system to detect worm and other malicious attacks. With the aim of identifying anomalous network traffic simply and effectively, a proved ‘‘join” strategy is also designed along with the two traffic statistic based intrusion detection algorithms. The whole IDS module is able to run with low computational complexity and high detection accuracy. Finally, we conduct experiments to verify the performance of our system. 2008 Elsevier B.V. All rights reserved.
منابع مشابه
nProbe: an Open Source NetFlow Probe for Gigabit Networks
Cisco NetFlow is an industry standard protocol suitable for monitoring network traffic. Although most of high-end network routers support NetFlow, very often flows are computed only on a small portion of the overall traffic due to performance limitation of NetFlow probe implementations. This paper covers the design and implementation of an open source software NetFlow probe designed for handlin...
متن کاملFlowRadar: A Better NetFlow for Data Centers
NetFlow has been a widely used monitoring tool with a variety of applications. NetFlow maintains an active working set of flows in a hash table that supports flow insertion, collision resolution, and flow removing. This is hard to implement in merchant silicon at data center switches, which has limited per-packet processing time. Therefore, many NetFlow implementations and other monitoring solu...
متن کاملReinventing NetFlow for OpenFlow Software-Defined Networks
Obtaining flow-level measurements, similar to those provided by Netflow/IPFIX, with OpenFlow is challenging as it requires the installation of an entry per flow in the flow tables. This approach does not scale well with the number of concurrent flows in the traffic as the number of entries in the flow tables is limited and small. Flow monitoring rules may also interfere with forwarding or other...
متن کاملReal-Time and Resilient Intrusion Detection: A Flow-Based Approach
Flow-based intrusion detection will play an important role in high-speed networks, due to the stringent performance requirements of packet-based solutions. Flow monitoring technologies, such as NetFlow or IPFIX, aggregate individual packets into flows, requiring new intrusion detection algorithms to deal with the aggregated data. These algorithms are subject to constraints on real-time and accu...
متن کاملTraffic monitor deployment in IP networks
This paper investigates the problem of deploying network traffic monitors with optimized coverage and cost in an IP network. Deploying a network-wide monitoring infrastructure in operational networks is necessary for practical reasons. We investigate two representative solutions, a router-based solution called NetFlow and an interface-based solution called CMON. Several cost factors are associa...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Computer Networks
دوره 52 شماره
صفحات -
تاریخ انتشار 2008