Design of a Stream-Based IP Flow Record Query Language

  • Authors:
  • Vladislav Marinov;Jürgen Schönwälder

  • Affiliations:
  • Computer Science, Jacobs University Bremen, Germany;Computer Science, Jacobs University Bremen, Germany

  • Venue:
  • DSOM '09 Proceedings of the 20th IFIP/IEEE International Workshop on Distributed Systems: Operations and Management: Integrated Management of Systems, Services, Processes and People in IT
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Analyzing Internet traffic has become an important and challenging task. NetFlow/IPFIX flow records are widely used to provide a summary of the Internet traffic carried on a link or forwarded by a router. Several tools exist to filter or to search for specific flows in a collection of flow records, however the filtering or query languages that these tools use have limited capabilities when it comes to describing more complex network activity. This paper proposes a framework and a new stream-based flow record query language, which allows certain types of traffic patterns to be defined and matched in a collection of flow records. The usage of the proposed new language is exemplified by constructing a query identifying the Blaster.A worm.