Practical Experience with IPFIX Flow Collectors
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F13%3A10130163" target="_blank" >RIV/63839172:_____/13:10130163 - isvavai.cz</a>
Result on the web
—
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
Practical Experience with IPFIX Flow Collectors
Original language description
As the number of Internet applications grows, the number of applications that use data encapsulation increases as well. Flow monitoring using NetFlow version 5 or 9 is only able to analyze the encapsulating protocol, therefore it becomes too limited to detect new threats. For this reason, more thorough knowledge of such traffic is needed. The IPFIX protocol can be used in such situations, because it provides enough flexibility for monitoring tools to be extended by new elements. Along with greater flexibility, IPFIX support results in a higher performance footprint on collectors and tools for querying the collected data. Currently, there is a lack of flow collection frameworks with IPFIX support that would allow flow data to be extended. The aim of this paper is to compare open-source flow collectors that provide support for the IPFIX protocol. We focus on evaluating performance of query tools and the level of IPFIX support provided by the collection frameworks.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
IN - Informatics
OECD FORD branch
—
Result continuities
Project
<a href="/en/project/LM2010005" target="_blank" >LM2010005: Large Infrastructure CESNET</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2013
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the 2013 IFIP/IEEE International Symposium on Integrated Network Management (IM 2013)
ISBN
978-1-4673-5229-1
ISSN
—
e-ISSN
—
Number of pages
6
Pages from-to
1021-1026
Publisher name
IEEE Xplore Digital Library
Place of publication
Ghent, Belgium
Event location
Gent, Belgie
Event date
May 27, 2013
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—