• DocumentCode
    3633405
  • Title

    Improving Host Profiling with Bidirectional Flows

  • Author

    Pavel Minarik;Jan Vykopal;Vojtech Krmicek

  • Author_Institution
    Inst. of Comput. Sci., Masaryk Univ., Brno, Czech Republic
  • Volume
    3
  • fYear
    2009
  • Firstpage
    231
  • Lastpage
    237
  • Abstract
    We present an approach to network devices behavior profiling based on NetFlow monitoring and a bidirectional flows extension. Behavior profiles of network devices typically focus on communicating peers, amount of traffic and traffic structure. However, using an implementation of the bidirectional flows standard we are able to distinguish between servers, clients and single flows directly which increases the profile quality. In this paper, we describe and evaluate our bidirectional flows implementation and suggest to use more precise time stamps in flow monitoring. Further, we compare results obtained by standard behavior profiles (unidirectional flows) and extended behavior profiles (bidirectional flows). Various measurements of extended behavior profile from campus network are presented. The influence of a sensor connection to themonitored network (Cisco SPAN port vs. tap) on the data quality is studied as a side effect of bidirectional flows implementation.
  • Keywords
    "Telecommunication traffic","Monitoring","Intrusion detection","Computer networks","Computer science","Electronic mail","Network servers","Protocols","Statistical analysis","Informatics"
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Engineering, 2009. CSE ´09. International Conference on
  • Print_ISBN
    978-1-4244-5334-4
  • Type

    conf

  • DOI
    10.1109/CSE.2009.23
  • Filename
    5283569