Implementation of a stream-based IP flow record query language

  • Authors:
  • Kaloyan Kanev;Nikolay Melnikov;Jürgen Schönwälder

  • Affiliations:
  • Computer Science, Jacobs University Bremen, Germany;Computer Science, Jacobs University Bremen, Germany;Computer Science, Jacobs University Bremen, Germany

  • Venue:
  • AIMS'10 Proceedings of the Mechanisms for autonomous management of networks and services, and 4th international conference on Autonomous infrastructure, management and security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Internet traffic analysis via flow records is an important task for network operators. There is a variety of applications, targeted at identifying, filtering or aggregating flows based on certain criteria. Most of these applications exhibit certain limitations when it comes to the identification of complex network activities. To overcome some of these limitations, a new flow query language has been proposed recently, which allows to express complex time relationships between flows. In this paper, we describe a prototype implementation of this query language and we evaluate its performance.