首页> 外文会议>IEEE Annual Ubiquitous Computing, Electronics Mobile Communication Conference >A Virtualized Network Function for Advanced Network Flow Logging in Microsoft Azure Distributed System
【24h】

A Virtualized Network Function for Advanced Network Flow Logging in Microsoft Azure Distributed System

机译:Microsoft Azure分布式系统中用于高级网络流日志记录的虚拟化网络功能

获取原文

摘要

Storing, viewing, and analyzing network flows in a Cloud environment is an important Virtualized Network Function (VNF) for Cloud tenants and users. It is used to store, track, and analyze traffic that belongs to Virtual Networks (VNETs), Virtual Machines (VMs), or Network Interfaces (NICs). It is used for logging ingress and egress IP traffic flows, number of bytes and packets transmitted and received, and network connections. Flow logging is critical for the investigation of firewall functionalities, security incidents, and threat detection. Moreover, it can be used for detecting connection and network anomalies such as connection outages, configuration changes, or malicious activities. Alerts can be fired for any suspicious network activities. Visualization of flows logs provides insights such as who is using a web-service or an application, when customers are logged in and out, and what are the geographical locations where connections are being initiated or terminated. In this paper, a novel method for VNF that details the framework for logging network flows in a Cloud environment is provided. The method aims at accommodating multiple and simulations Cloud tenants and enabling the logging of network flows while at the same time accommodates high incoming rates of flow events and data. One of the major benefits of this new method is that it supports high number of flows per second that facilitates flow logging of high traffic volumes. Not only customers can experience higher number of flows logged, but the flow logs are visualized and contain the number of packets and bytes transmitted and received for outbound and inbound flows, respectively.
机译:对于云租户和用户,在云环境中存储,查看和分析网络流是一项重要的虚拟化网络功能(VNF)。它用于存储,跟踪和分析属于虚拟网络(VNET),虚拟机(VM)或网络接口(NIC)的流量。它用于记录入口和出口IP流量,发送和接收的字节数和数据包数以及网络连接。流日志对于调查防火墙功能,安全事件和威胁检测至关重要。此外,它可用于检测连接和网络异常,例如连接中断,配置更改或恶意活动。可以针对任何可疑的网络活动触发警报。流日志的可视化提供了洞察力,例如谁在使用Web服务或应用程序,何时登录和注销客户,以及发起或终止连接的地理位置是什么。本文提供了一种新的VNF方法,详细介绍了在云环境中记录网络流的框架。该方法旨在容纳多个和模拟的云租户,并启用网络流量日志记录,同时容纳流量事件和数据的高传入速率。这种新方法的主要优点之一是它支持每秒高流量,从而有助于记录高流量。不仅客户可以体验到更多的日志流,而且可以直观地看到流日志,并分别包含针对出站和入站流发送和接收的数据包和字节数。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号