Title of article :
TIFAflow: Enhancing Traffic Archiving System with Flow Granularity for Forensic Analysis in Network Security
Author/Authors :
Chen, Zhen Tsinghua University - Research Institute ofInformation Technology - Tsinghua National Laboratoryfor Information Science and Technology (TNList), China , Ruan, Lingyun Purdue University - Department of Computer Science, USA , Cao, Junwei Tsinghua University - Research Institute ofInformation Technology - Tsinghua National Laboratory for Information Science and Technology (TNList), China , Yu, Yifan Tsinghua University - Department of Electronic Engineering and Tsinghua National Laboratory for Information Science andTechnology (TNList), China , Jiang, Xin Tsinghua University - Department of Computer Science and Technology, Research Institute of Information Technology and Tsinghua National Laboratory for Information Science and Technology (TNList), China
From page :
406
To page :
417
Abstract :
The archiving of Internet traffic is an essential function for retrospective network event analysis andforensic computer communication. The state-of-the-art approach for network monitoring and analysis involves storage and analysis of network flow statistic. However, this approach loses much valuable information within the Internet traffic. With the advancement of commodity hardware, in particular the volume of storage devices and the speed of interconnect technologies used in network adapter cards and multi-core processors, it is now possible to capture 10 Gbps and beyond real-time network traffic using a commodity computer, such as n2disk. Also with the advancement of distributed file system (such as Hadoop, ZFS, etc.) and open cloud computing platform (such as OpenStack, CloudStack, and Eucalyptus, etc.), it is practical to store such large volume of traffic data and fully in-depth analyse the inside communication within an acceptable latency. In this paper, based on wellknown TimeMachine, we present TIFAflow, the design and implementation of a novel system for archiving and querying network flows. Firstly, we enhance the traffic archiving system named TImemachine+FAstbit (TIFA) with flow granularity, i.e., supply the system with flow table and flow module. Secondly, based on real network traces, we conduct performance comparison experiments of TIFAflow with other implementations such as common database solution, TimeMachine and TIFA system. Finally, based on comparison results, we demonstrate that TIFAflow has a higher performance improvement in storing and querying performance than TimeMachine and TIFA, both in time and space metrics.
Keywords :
network security , traffic archival , forensic analysis , phishing attack , bitmap database , hadoop distributed file system , cloud computing , NoSQL
Journal title :
Tsinghua Science and Technology
Journal title :
Tsinghua Science and Technology
Record number :
2535557
Link To Document :
بازگشت