• DocumentCode
    2693572
  • Title

    SCRIPT: A framework for Scalable Real-time IP Flow Record Analysis

  • Author

    Morariu, Cristian ; Racz, Peter ; Stiller, Burkhard

  • Author_Institution
    Dept. of Inf. IFI, Univ. of Zurich, Zürich, Switzerland
  • fYear
    2010
  • fDate
    19-23 April 2010
  • Firstpage
    278
  • Lastpage
    285
  • Abstract
    Analysis of IP traffic is highly important, since it determines the starting point of many network management operations, such as intrusion detection, network planning, network monitoring, or accounting and billing. One of the most utilized metering data formats in analysis applications are IP (Internet Protocol) flow records. With the increase of IP traffic, such traffic analysis applications need to cope with a constantly increasing number of flow records. Typically, centralized approaches to IP traffic analysis have scalability problems, which are addressed by replacing existing hardware with more powerful CPUs and faster memory. In contrast, this paper developed and implemented SCRIPT (Scalable Real-time IP Flow Record Analysis), which defines a scalable analysis framework that can be used to distribute flow records to multiple nodes performing traffic analysis in order to balance the overall workload among those nodes. Due to its generic design, the framework developed can be extended and used to distribute other metering data, such as packet headers, payloads, or accounting records.
  • Keywords
    IP networks; computer network management; telecommunication network planning; telecommunication network routing; telecommunication traffic recording; Internet protocol; SCRIPT; intrusion detection; network management; network monitoring; network planning; packet headers; scalable real-time IP flow record analysis; traffic analysis; Data analysis; Hardware; Internet; Intrusion detection; Monitoring; Payloads; Performance analysis; Protocols; Scalability; Telecommunication traffic; Distributed Analysis; IP Flow Accounting; Peer-to-Peer;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (NOMS), 2010 IEEE
  • Conference_Location
    Osaka
  • ISSN
    1542-1201
  • Print_ISBN
    978-1-4244-5366-5
  • Electronic_ISBN
    1542-1201
  • Type

    conf

  • DOI
    10.1109/NOMS.2010.5488476
  • Filename
    5488476