IPFIX and DPI Information in a Big Data Environment
Abstract
The problem: How can we more precisely identify aspects of network behavior without giving up the size and coverage benefits of network flow? Conclusions: There are a variety of approaches for enriching flow data. Using flow data with DPI information balances storage volume against precision. This will improve the degree of actionability for the results. This may also slow down production of some results as data volume increases.
Document Details
- Document Type
- Technical Report
- Publication Date
- Jan 09, 2023
- Accession Number
- AD1189558
Entities
People
- Katherine Prevost
- Timothy Shimeall
Organizations
- Carnegie Mellon University