Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Combining Cisco NetFlow Exports with Relational Database Technology for Usage Statistics, Intrusion Detection, and Network Forensics

Argonne National Laboratory operates a complex internal network with a large number of external network peerings. A requirement of this network is that it be monitored with minimal impact on traffic. Cisco NetFlow technology provides the information necessary to monitor such a network, but the data from NetFlow must be captured and analyzed. We present a system that uses a high-powered relational database to manage the data. Our primary motivations in building this system were to learn whether or not database technology was an appropriate tool for this situation and to understand what types of questions about the network could be answered with such a system.

This work was supported by the Mathematical, Information, and Computational Sciences Division subprogram of the Office of Advanced Scientific Computing Research, U.S. Department of Energy, under Contract W-31-109-Eng-38.

Bill Nickless, Argonne National Laboratory

John-Paul Navarro, Argonne National Laboratory

Linda Winkler, Argonne National Laboratory

BibTeX
@inproceedings {271108,
author = {Bill Nickless and John-Paul Navarro and Linda Winkler},
title = {Combining Cisco {NetFlow} Exports with Relational Database Technology for Usage Statistics, Intrusion Detection, and Network Forensics},
booktitle = {14th Systems Administration Conference (LISA 2000)},
year = {2000},
address = {New Orleans, LA},
url = {https://www.usenix.org/conference/lisa-2000/combining-cisco-netflow-exports-relational-database-technology-usage-statistics},
publisher = {USENIX Association},
month = dec
}
Download

Links

Paper: 
http://www.usenix.org/events/lisa2000/full_papers/navarro/navarro.pdf
Paper (HTML): 
http://www.usenix.org/events/lisa2000/full_papers/navarro/navarro_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

LISA is a registered trademark of the USENIX Association.

  • Privacy Policy
  • Contact Us