Detection of Network Flow Timestamp Reliability - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2014

Detection of Network Flow Timestamp Reliability

Martin Žádnik
  • Fonction : Auteur
  • PersonId : 994069
Erik Šabik
  • Fonction : Auteur
Václav Bartoš
  • Fonction : Auteur
  • PersonId : 994070

Résumé

Network flow measurement and analysis are important parts of network management and security. Flow data analysis is a challenging task which is often rendered harder by pitfalls in a monitoring pipeline. In this paper we focus on timestamps since many analysis procedures utilize timestamps to reveal various characteristics of network traffic. Unfortunately, the timestamps are not always that reliable as it may seem. We propose an algorithm to estimate the percentage of correctly assigned timestamps to flow records with respect to the sequence of a request and a response flow. We simulate various timestamp failures and we evaluate the failures using the proposed algorithm. We demonstrate the usage of the algorithm in the use case of bidirectional flow orientation.
Fichier principal
Vignette du fichier
978-3-662-43862-6_18_Chapter.pdf (149.9 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01401301 , version 1 (23-11-2016)

Licence

Paternité

Identifiants

Citer

Martin Žádnik, Erik Šabik, Václav Bartoš. Detection of Network Flow Timestamp Reliability. 8th IFIP International Conference on Autonomous Infrastructure, Management and Security (AIMS), Jun 2014, Brno, Czech Republic. pp.147-159, ⟨10.1007/978-3-662-43862-6_18⟩. ⟨hal-01401301⟩
138 Consultations
99 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More