Title :
Improving Host Profiling with Bidirectional Flows
Author :
Pavel Minarik;Jan Vykopal;Vojtech Krmicek
Author_Institution :
Inst. of Comput. Sci., Masaryk Univ., Brno, Czech Republic
Abstract :
We present an approach to network devices behavior profiling based on NetFlow monitoring and a bidirectional flows extension. Behavior profiles of network devices typically focus on communicating peers, amount of traffic and traffic structure. However, using an implementation of the bidirectional flows standard we are able to distinguish between servers, clients and single flows directly which increases the profile quality. In this paper, we describe and evaluate our bidirectional flows implementation and suggest to use more precise time stamps in flow monitoring. Further, we compare results obtained by standard behavior profiles (unidirectional flows) and extended behavior profiles (bidirectional flows). Various measurements of extended behavior profile from campus network are presented. The influence of a sensor connection to themonitored network (Cisco SPAN port vs. tap) on the data quality is studied as a side effect of bidirectional flows implementation.
Keywords :
"Telecommunication traffic","Monitoring","Intrusion detection","Computer networks","Computer science","Electronic mail","Network servers","Protocols","Statistical analysis","Informatics"
Conference_Titel :
Computational Science and Engineering, 2009. CSE ´09. International Conference on
Print_ISBN :
978-1-4244-5334-4
DOI :
10.1109/CSE.2009.23