SiLK: A Tool Suite for Unsampled Network Flow Analysis at Scale
SiLK: A Tool Suite for Unsampled Network Flow Analysis at Scale
复制标题
SiLK:用于大规模非采样网络流量分析的工具套件
DOI:
10.1109/bigdata.congress.2014.34
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
K. Prevost
中科院分区:
文献类型:
--
作者:
Mark Thomas;Leigh Metcalf;Jonathan M. Spring;P. Krystosek;K. Prevost
A large organization can generate over ten billion network flow records per day, a high-velocity data source. Finding useful, security-related anomalies in this volume of data is challenging. Most large network flow tools sample the data to make the problem manageable, but sampling unacceptably reduces the fidelity of analytic conclusions. In this paper we discuss SiLK, a tool suite created to analyze this high-volume data source without sampling. SiLK implementation and architectural design are optimized to manage this Big Data problem. SiLK provides not just network flow capture and analysis, but also includes tools to analyze large sets and dictionaries that frequently relate to network flow data, incorporating higher-variety data sources. These tools integrate disparate data sources with SiLK analysis.