TIFAflow: Enhancing Traffic Archiving System with Flow Granularity for Forensic Analysis in Network Security

被引:9
作者
Chen, Zhen [1 ,2 ]
Ruan, Lingyun [2 ,3 ]
Cao, Junwei [1 ,2 ]
Yu, Yifan [2 ,4 ]
Jiang, Xin [2 ,5 ]
机构
[1] Tsinghua Univ, Res Inst Informat Technol, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Tsinghua Natl Lab Informat Sci & Technol TNList, Beijing 100084, Peoples R China
[3] Tsinghua Univ, Res Inst Informat Technol, Dept Automat, Beijing 100084, Peoples R China
[4] Tsinghua Univ, Dept Elect Engn, Beijing 100084, Peoples R China
[5] Tsinghua Univ, Res Inst Informat Technol, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
network security; traffic archival; forensic analysis; phishing attack; bitmap database; hadoop distributed file system; cloud computing; NoSQL;
D O I
10.1109/TST.2013.6574679
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The archiving of Internet traffic is an essential function for retrospective network event analysis and forensic computer communication. The state-of-the-art approach for network monitoring and analysis involves storage and analysis of network flow statistic. However, this approach loses much valuable information within the Internet traffic. With the advancement of commodity hardware, in particular the volume of storage devices and the speed of interconnect technologies used in network adapter cards and multi-core processors, it is now possible to capture 10 Gbps and beyond real-time network traffic using a commodity computer, such as n2disk. Also with the advancement of distributed file system (such as Hadoop, ZFS, etc.) and open cloud computing platform (such as OpenStack, CloudStack, and Eucalyptus, etc.), it is practical to store such large volume of traffic data and fully in-depth analyse the inside communication within an acceptable latency. In this paper, based on well-known TimeMachine, we present TIFAflow, the design and implementation of a novel system for archiving and querying network flows. Firstly, we enhance the traffic archiving system named TImemachine+FAstbit (TIFA) with flow granularity, i.e., supply the system with flow table and flow module. Secondly, based on real network traces, we conduct performance comparison experiments of TIFAflow with other implementations such as common database solution, TimeMachine and TIFA system. Finally, based on comparison results, we demonstrate that TIFAflow has a higher performance improvement in storing and querying performance than TimeMachine and TIFA, both in time and space metrics.
引用
收藏
页码:406 / 417
页数:12
相关论文
共 36 条
[1]  
[Anonymous], TRUSTED SYSTEMS
[2]  
[Anonymous], P USENIX ANN TECHN C
[3]  
[Anonymous], ECRIME RES SUMMIT EC
[4]  
[Anonymous], 50 RIPE M STOCKH SWE
[5]  
[Anonymous], 2009, P 6 C EM ANTISPAM CE
[6]  
[Anonymous], ECRIME RES SUMMIT EC
[7]  
[Anonymous], COMPUTER NETWORKS
[8]  
[Anonymous], USENIX ANN TECHN C M
[9]  
[Anonymous], P 13 ACM SIGCOMM CIN
[10]  
[Anonymous], NETWORKING DISTRIBUT