Design of an IP Flow Record Query Language

  • Authors:
  • Vladislav Marinov;Jürgen Schönwälder

  • Affiliations:
  • Computer Science, Jacobs University Bremen, Germany;Computer Science, Jacobs University Bremen, Germany

  • Venue:
  • AIMS '08 Proceedings of the 2nd international conference on Autonomous Infrastructure, Management and Security: Resilient Networks and Services
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Internet traffic is often summarized by collecting NetFlow/IPFIX flow records. Several tools exist to filter or to search for specific flows in a collection of flow records. However, there is a need for a framework (filter language) which allows certain types of traffic patterns to be defined and matched in a collection of flow records. The goal of this project is to research the various filter/query languages used by tools or proposed in the literature and to extract a common basis for a new orthogonal flow record query language. We present research motivation and state of the art in this paper.