ENTRADA: A high-performance network traffic data streaming warehouse

ENTRADA: A high-performance network traffic data streaming warehouse
复制标题

DOI:
10.1109/noms.2016.7502925
复制
发表时间:
2016-07
期刊:
NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
影响因子:
--
通讯作者:
M. Wullink;G. Moura;M. Müller;Cristian Hesselman
M. Wullink;G. Moura;M. Müller;Cristian Hesselman
中科院分区:
其他
文献类型:
--
作者:
M. Wullink;G. Moura;M. Müller;Cristian Hesselman

文献摘要

被引文献

相似文献

我们提出了Entrada,这是一个高性能的数据流仓库,使研究人员和运营商能够在交互式响应时间(秒至几分钟)内分析大量的网络流量和测量数据,即使在小型计算机集群中也可以通过使用此类性能。优化的文件格式和高性能查询引擎,这两种开源都已经运行了1.5年以上在我们讨论的两个.NL DNS的PCAP文件中,我们在本文中提高了.NL区域的安全性和稳定性。最终,我们开源的Entrada可以使用研究人员,操作员和注册表来使用其“开箱即用”,以部署自己的网络分析群集轻松扩展以处理任何其他结构化数据。
We present ENTRADA, a high-performance data streaming warehouse that enables researchers and operators to analyze vast amounts of network traffic and measurement data within interactive response times (seconds to few minutes), even in a small computer cluster. ENTRADA delivers such performance by employing a optimized file format and a high-performance query engine, both open-source. ENTRADA has been operational for more than 1.5 years, having ingested more than 100 TB of pcap files from two .nl DNS authoritative servers. As we discuss, we use this data in projects that aim at further increasing the security and stability of the .nl zone. We present in this paper our design choices, experiences, and a performance evaluation of ENTRADA. Finally, we open-source ENTRADA, which can be used “out-of-the-box” by researchers, operators, and registries to deploy their own networking analysis clusters for DNS traffic, and can be easily extended to handle any other structured data.