{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T10:39:52Z","timestamp":1743071992868,"version":"3.40.3"},"publisher-location":"Cham","reference-count":15,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319607733"},{"type":"electronic","value":"9783319607740"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Flow based monitoring is currently a standard approach suitable for large networks of ISP size. The main advantage of flow processing is a smaller amount of data due to aggregation. There are many reasons (such as huge volume of transferred data, attacks represented by many flow records) to develop scalable systems that can process flow data in parallel. This paper deals with splitting a stream of flow data in order to perform parallel anomaly detection on distributed computational nodes. Flow data distribution is focused not only on uniformity but mainly on successful detection. The results of an experimental analysis show that the proposed approach does not break important semantic relations between individual flow records and therefore it preserves detection results. All experiments were performed using real data traces from Czech National Education and Research Network.<\/jats:p>","DOI":"10.1007\/978-3-319-60774-0_1","type":"book-chapter","created":{"date-parts":[[2017,6,16]],"date-time":"2017-06-16T12:23:19Z","timestamp":1497615799000},"page":"3-15","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Making Flow-Based Security Detection Parallel"],"prefix":"10.1007","author":[{"given":"Marek","family":"\u0160vepe\u0161","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tom\u00e1\u0161","family":"\u010cejka","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,6,17]]},"reference":[{"key":"1_CR1","doi-asserted-by":"publisher","unstructured":"Munz, G., Carle, G.: Real-time analysis of flow data for network attack detection. In: 2007 10th IFIP\/IEEE International Symposium on Integrated Network Management, pp. 100\u2013108, May 2007. doi:10.1109\/INM.2007.374774","DOI":"10.1109\/INM.2007.374774"},{"key":"1_CR2","doi-asserted-by":"publisher","unstructured":"Cejka, T., Bartos, V., Svepes, M., Rosa, Z., Kubatova, H.: NEMEA: a framework for network traffic analysis. In: 2016 12th International Conference on Network and Service Management (CNSM), pp. 195\u2013201, October 2016. doi:10.1109\/CNSM.2016.7818417","DOI":"10.1109\/CNSM.2016.7818417"},{"issue":"1","key":"1_CR3","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1109\/TDSC.2006.6","volume":"3","author":"K Xinidis","year":"2006","unstructured":"Xinidis, K., Charitakis, I., Antonatos, S., Anagnostakis, K.G., Markatos, E.P.: An active splitter architecture for intrusion detection and prevention. IEEE Trans. Dependable Secure Comput. 3(1), 31\u201344 (2006). doi:10.1109\/TDSC.2006.6","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"1_CR4","unstructured":"Roesch, M.: Snort - lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration, LISA 1999, Berkeley, CA, USA, pp. 229\u2013238. USENIX Association (1999)"},{"issue":"8","key":"1_CR5","first-page":"9","volume":"9","author":"H Sallay","year":"2009","unstructured":"Sallay, H., Alshalfan, K.A., Fred, O.B., Words, K.: A scalable distributed IDS architecture for high speed networks. IJCSNS Int. J. Comput. SciNetw. Secur. 9(8), 9\u201316 (2009)","journal-title":"IJCSNS Int. J. Comput. SciNetw. Secur."},{"key":"1_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"537","DOI":"10.1007\/978-3-642-21928-3_39","volume-title":"Computational Science and Its Applications - ICCSA 2011","author":"N-U Kim","year":"2011","unstructured":"Kim, N.-U., Jung, S.-M., Chung, T.-M.: An efficient hash-based load balancing scheme to support parallel NIDS. In: Murgante, B., Gervasi, O., Iglesias, A., Taniar, D., Apduhan, B.O. (eds.) ICCSA 2011. LNCS, vol. 6782, pp. 537\u2013549. Springer, Heidelberg (2011). doi:10.1007\/978-3-642-21928-3_39"},{"key":"1_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/978-3-540-74320-0_6","volume-title":"Recent Advances in Intrusion Detection","author":"M Vallentin","year":"2007","unstructured":"Vallentin, M., Sommer, R., Lee, J., Leres, C., Paxson, V., Tierney, B.: The NIDS cluster: scalable, stateful network intrusion detection on commodity hardware. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 107\u2013126. Springer, Heidelberg (2007). doi:10.1007\/978-3-540-74320-0_6"},{"issue":"23\u201324","key":"1_CR8","doi-asserted-by":"publisher","first-page":"2435","DOI":"10.1016\/S1389-1286(99)00112-7","volume":"31","author":"V Paxson","year":"1999","unstructured":"Paxson, V.: Bro: a system for detecting network intruders in real-time. Comput. Netw. 31(23\u201324), 2435\u20132463 (1999). doi:10.1016\/S1389-1286(99)00112-7","journal-title":"Comput. Netw."},{"key":"1_CR9","unstructured":"Apache: Hadoop. http:\/\/hadoop.apache.org"},{"key":"1_CR10","unstructured":"Apache: Spark. http:\/\/spark.apache.org"},{"key":"1_CR11","doi-asserted-by":"publisher","unstructured":"Fontugne, R., Mazel, J., Fukuda, K.: Hashdoop: a MapReduce framework for network anomaly detection. In: IEEE Conference on Computer Communications Workshops (INFOCOM) (2014). doi:10.1109\/INFCOMW.2014.6849281","DOI":"10.1109\/INFCOMW.2014.6849281"},{"issue":"12","key":"1_CR12","doi-asserted-by":"publisher","first-page":"2285","DOI":"10.1109\/JSAC.2006.884027","volume":"24","author":"J Mai","year":"2006","unstructured":"Mai, J., Sridharan, A., Chuah, C.N., Zang, H., Ye, T.: Impact of packet sampling on portscan detection. IEEE J. Sel. Areas Commun. 24(12), 2285\u20132298 (2006). doi:10.1109\/JSAC.2006.884027","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"1_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1007\/978-3-642-28534-9_11","volume-title":"Traffic Monitoring and Analysis","author":"K Bartos","year":"2012","unstructured":"Bartos, K., Rehak, M.: Towards efficient flow sampling technique for anomaly detection. In: Pescap\u00e8, A., Salgarelli, L., Dimitropoulos, X. (eds.) TMA 2012. LNCS, vol. 7189, pp. 93\u2013106. Springer, Heidelberg (2012). doi:10.1007\/978-3-642-28534-9_11"},{"key":"1_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-319-39814-3_19","volume-title":"Management and Security in the Age of Hyperconnectivity","author":"T Cejka","year":"2016","unstructured":"Cejka, T., Svepes, M.: Analysis of vertical scans discovered by naive detection. In: Badonnel, R., Koch, R., Pras, A., Dra\u0161ar, M., Stiller, B. (eds.) AIMS 2016. LNCS, vol. 9701, pp. 165\u2013169. Springer, Cham (2016). doi:10.1007\/978-3-319-39814-3_19"},{"key":"1_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1007\/978-3-642-30633-4_21","volume-title":"Dependable Networks and Services","author":"P Velan","year":"2012","unstructured":"Velan, P., Krej\u010d\u00ed, R.: Flow information storage assessment using IPFIXcol. In: Sadre, R., Novotn\u00fd, J., \u010celeda, P., Waldburger, M., Stiller, B. (eds.) AIMS 2012. LNCS, vol. 7279, pp. 155\u2013158. Springer, Heidelberg (2012). doi:10.1007\/978-3-642-30633-4_21"}],"container-title":["Lecture Notes in Computer Science","Security of Networks and Services in an All-Connected World"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-60774-0_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,11]],"date-time":"2023-07-11T14:03:17Z","timestamp":1689084197000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-60774-0_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319607733","9783319607740"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-60774-0_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"17 June 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"AIMS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Autonomous Infrastructure, Management and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Zurich","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Switzerland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 July 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 July 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"aims2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}