Real-time analysis of flow data for network attack detection

Gerhard Münz, Georg Carle

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

52 Scopus citations

Abstract

With the wide deployment of flow monitoring in IP networks, the analysis of the exported flow data has become an important research area. It has been shown that flow data can be used to detect traffic anomalies, DoS attacks, and the propagation of worms. In practice, anomalies and attacks should be detected as fast as possible in order to allow taking appropriate countermeasures. We describe the necessary steps from the raw flow data to the detection result in a systematic way. Furthermore, we present TOPAS, a system and framework for real-time analysis of flow data, that has been developed in order to meet these requirements. Performance measurements and various application examples point out the capabilities and benefits of our approach.

Original languageEnglish
Title of host publication10th IFIP/IEEE International Symposium on Integrated Network Management 2007, IM '07
Pages100-108
Number of pages9
DOIs
StatePublished - 2007
Externally publishedYes
Event10th IFIP/IEEE International Symposium on Integrated Network Management 2007, IM '07 - Munich, Germany
Duration: 21 May 200725 May 2007

Publication series

Name10th IFIP/IEEE International Symposium on Integrated Network Management 2007, IM '07

Conference

Conference10th IFIP/IEEE International Symposium on Integrated Network Management 2007, IM '07
Country/TerritoryGermany
CityMunich
Period21/05/0725/05/07

Keywords

  • Anomaly and attack detection
  • Flow analysis
  • Network monitoring

Fingerprint

Dive into the research topics of 'Real-time analysis of flow data for network attack detection'. Together they form a unique fingerprint.

Cite this