Massive Scale Cyber Traffic Analysis: A Driver for Graph Database Research
We describe the significance and prominence of network traffic analysis (TA) as a graph- and network-theoretical domain for advancing research in graph database systems. TA involves observing and analyzing the connections between clients, servers, hosts, and actors within IP networks, both at particular times and as extended over times. Towards that end, NetFlow (or more generically, IPFLOW) data are available from routers and servers which summarize coherent groups of IP packets flowing through the network. IPFLOW databases are routinely interrogated statistically and visualized for suspicious patterns. But the ability to cast IPFLOW data as a massive graph and query it interactively, in order to e.g.\ identify connectivity patterns, is less well advanced, due to a number of factors including scaling, and their hybrid nature combining graph connectivity and quantitative attributes. In this paper, we outline requirements and opportunities for graph-structured IPFLOW analytics based on our experience with real IPFLOW databases. Specifically, we describe real use cases from the security domain, cast them as graph patterns, show how to express them in two graph-oriented query languages SPARQL and Datalog, and use these examples to motivate a new class of "hybrid" graph-relational systems.
- Research Organization:
- Pacific Northwest National Laboratory (PNNL), Richland, WA (US)
- Sponsoring Organization:
- USDOE
- DOE Contract Number:
- AC05-76RL01830
- OSTI ID:
- 1089074
- Report Number(s):
- PNNL-SA-94818; 400470000
- Country of Publication:
- United States
- Language:
- English
Similar Records
Discrete Mathematical Approaches to Graph-Based Traffic Analysis
HodDB: Design and Analysis of a Query Processor for Brick.
Building a simulator control station using the TCL/TK language
Conference
·
Tue Apr 01 00:00:00 EDT 2014
·
OSTI ID:1222143
HodDB: Design and Analysis of a Query Processor for Brick.
Conference
·
Tue Nov 07 23:00:00 EST 2017
· Proceedings of The 4th International Conference on Systems for Energy-Efficient Built Environments (BuildSys ‘17)
·
OSTI ID:1420425
Building a simulator control station using the TCL/TK language
Conference
·
Tue Mar 31 23:00:00 EST 1998
·
OSTI ID:319813