Publication Details

A Scalable Architecture for Network Traffic Forensics

LETAVAY Viliam, PLUSKAL Jan and RYŠAVÝ Ondřej. A Scalable Architecture for Network Traffic Forensics. In: The Fifteenth International Conference on Networking and Services ICNS 2019. Athens: The International Academy, Research and Industry Association, 2019, pp. 32-36. ISBN 978-1-61208-711-5.
Czech title
Škálovatelná architektura pro zpracování síťově forenzních dat
Type
conference paper
Language
english
Authors
Keywords

Network forensic analysis, Network trafc processing, Actor model

Abstract

Availability of high-speed Internet enables new opportunities for various cybercrime activities. Security administrators and LEA (Law Enforcement Agency) officers call for powerful tools capable of providing network communication analysis of an enormous amount of network traffic moreover, capable of analyzing an incomplete network data. 
Big data technologies were considered to implement tools for capturing, processing and storing packet traces representing network communication. Often, these systems are resource intensive requiring a significant amount of memory, computing power, and disk space. Presented paper describes a novel approach to real-time network traffic processing implemented in a distributed environment. The key difference to most existing systems is that the system is based on a light-weight actor model. The whole processing pipeline is represented in terms of actor nodes that can run in parallel. Also, actor-model offers a solution that is highly configurable and scalable. 
The preliminary evaluation of a prototype implementation supports these general statements.

Published
2019
Pages
32-36
Proceedings
The Fifteenth International Conference on Networking and Services ICNS 2019
Conference
The Fifteenth International Conference on Networking and Services ICNS 2019, Athens, GR
ISBN
978-1-61208-711-5
Publisher
The International Academy, Research and Industry Association
Place
Athens, GR
BibTeX
@INPROCEEDINGS{FITPUB11927,
   author = "Viliam Letavay and Jan Pluskal and Ond\v{r}ej Ry\v{s}av\'{y}",
   title = "A Scalable Architecture for Network Traffic Forensics",
   pages = "32--36",
   booktitle = "The Fifteenth International Conference on Networking and Services ICNS 2019",
   year = 2019,
   location = "Athens, GR",
   publisher = "The International Academy, Research and Industry Association",
   ISBN = "978-1-61208-711-5",
   language = "english",
   url = "https://www.fit.vut.cz/research/publication/11927"
}
Files
Back to top