首页> 外文期刊>IEEE transactions on network and service management >Exploring Network-Wide Flow Data With Flowyager
【24h】

Exploring Network-Wide Flow Data With Flowyager

机译:使用Flumyager探索网络范围的流量数据

获取原文
获取原文并翻译 | 示例

摘要

Many network operations, ranging from attack investigation and mitigation to traffic management, require answering network-wide flow queries in seconds. Although flow records are collected at each router, using available traffic capture utilities, querying the resulting datasets from hundreds of routers across sites and over time, remains a significant challenge due to the sheer traffic volume and distributed nature of flow records. In this article, we investigate how to improve the response time for a priori unknown network-wide queries. We present Flowyager, a system that is built on top of existing traffic capture utilities. Flowyager generates and analyzes tree data structures, that we call Flowtrees, which are succinct summaries of the raw flow data available by capture utilities. Flowtrees are self-adjusted data structures that drastically reduce space and transfer requirements, by 75% to 95%, compared to raw flow records. Flowyager manages the storage and transfers of Flowtrees, supports Flowtree operators, and provides a structured query language for answering flow queries across sites and time periods. By deploying a Flowyager prototype at both a large Internet Exchange Point and a Tier-1 Internet Service Provider, we showcase its capabilities for networks with hundreds of router interfaces. Our results show that the query response time can be reduced by an order of magnitude when compared with alternative data analytics platforms. Thus, Flowyager enables interactive network-wide queries and offers unprecedented drill-down capabilities to, e.g., identify DDoS culprits, pinpoint the involved sites, and determine the length of the attack.
机译:许多网络运营,从攻击调查和减缓到流量管理,需要在几秒钟内回答网络范围的流量查询。虽然在每个路由器处收集流量记录,但使用可用的流量捕获实用程序,但从站点的数百个路由器查询生成的数据集,随着时间的推移,仍然是由于流量记录的纯粹流量和分布式性质而导致的重大挑战。在本文中,我们调查如何提高先验未知网络范围查询的响应时间。我们呈现Flulyager,该系统建立在现有流量捕获实用程序之上。 Flulyager生成并分析树数据结构,即我们调用Flowtree,这是捕获实用程序可用的原始流量数据的简洁摘要。与原始流量记录相比,FlowTre是自调节数据结构,可大大降低空间和转移要求,达到75%至95%。 Flulyager管理FlowTrees的存储和传输,支持FlowTree运算符,并提供结构化查询语言,用于在站点和时间段内应答流量查询。通过在大型互联网交换点和一级互联网服务提供商中部署Fludyager原型,我们为具有数百个路由器接口的网络展示了它的功能。我们的结果表明,与替代数据分析平台相比,查询响应时间可以减少幅度级。因此,Flulyager使交互式网络范围的查询能够提供前所未有的钻取能力,例如,识别DDOS Culprits,查明所涉及的站点,并确定攻击的长度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号