SiLK: A Tool Suite for Unsampled Network Flow Analysis at Scale

SiLK: A Tool Suite for Unsampled Network Flow Analysis at Scale
复制标题

SiLK:用于大规模非采样网络流量分析的工具套件

DOI:
10.1109/bigdata.congress.2014.34
复制
发表时间:
2014
期刊:
2014 IEEE International Congress on Big Data
影响因子:
--
通讯作者:
K. Prevost
K. Prevost
中科院分区:
--
文献类型:
--
作者:
Mark Thomas;Leigh Metcalf;Jonathan M. Spring;P. Krystosek;K. Prevost

文献摘要

被引文献

相似文献

一个大型组织每天可以产生超过100亿个网络流记录,这是一个高速数据源。在此数据卷中发现有用的,与安全有关的异常是具有挑战性的。大多数大型网络流量工具采样了数据以使问题可以管理,但是对进行采样可听到,可以降低分析结论的保真度。在本文中,我们讨论了丝绸,这是一个工具套件,可以在不进行抽样的情况下创建用于分析此大量数据源的工具套件。丝绸实施和建筑设计已进行了优化,以解决此大数据问题。丝绸不仅提供网络流捕获和分析,还包括分析与网络流数据相关的大型集合和词典的工具,并结合了更高的不同数据源。这些工具将不同的数据源与丝绸分析集成在一起。
A large organization can generate over ten billion network flow records per day, a high-velocity data source. Finding useful, security-related anomalies in this volume of data is challenging. Most large network flow tools sample the data to make the problem manageable, but sampling unacceptably reduces the fidelity of analytic conclusions. In this paper we discuss SiLK, a tool suite created to analyze this high-volume data source without sampling. SiLK implementation and architectural design are optimized to manage this Big Data problem. SiLK provides not just network flow capture and analysis, but also includes tools to analyze large sets and dictionaries that frequently relate to network flow data, incorporating higher-variety data sources. These tools integrate disparate data sources with SiLK analysis.