Stream4Flow: Real-time IP Flow Host Monitoring using Apache Spark
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14610%2F18%3A00106894" target="_blank" >RIV/00216224:14610/18:00106894 - isvavai.cz</a>
Result on the web
<a href="http://dx.doi.org/10.1109/NOMS.2018.8406132" target="_blank" >http://dx.doi.org/10.1109/NOMS.2018.8406132</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/NOMS.2018.8406132" target="_blank" >10.1109/NOMS.2018.8406132</a>
Alternative languages
Result language
angličtina
Original language name
Stream4Flow: Real-time IP Flow Host Monitoring using Apache Spark
Original language description
In this paper, we present Stream4Flow, a framework for cyber situational awareness based on Apache Spark Streaming. We demonstrate utilization of Stream4Flow for real-time IP flow host monitoring in a large campus network. Contemporary IP flow analysis systems are not designed for the continuous host monitoring. Gaining the detailed overview of each host is not straightforward with these systems due to connection-based paradigm and performance challenges. We show that distributed stream processing is a natural solution for detailed IP flow host monitoring. Moreover, we describe a real-time host monitoring workflow in data streams in detail and present advantages of flow-based host monitoring in Apache Spark including real-time host profiling, dynamic level of detail and granularity.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/VI20162019014" target="_blank" >VI20162019014: Simulation, detection, and mitigation of cyber threats endangering critical infrastructure</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2018
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium
ISBN
9781538634165
ISSN
—
e-ISSN
—
Number of pages
2
Pages from-to
1-2
Publisher name
IEEE
Place of publication
Taipei, Taiwan
Event location
Taipei, Taiwan
Event date
Jan 1, 2018
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—