A Method for Analyzing Network Traffic Using Cardinality Information in Firewall Logs
Satoshi Matsumoto, Akira Sato, Yasushi Shinjo, Nakai Hisashi, Kozo Itano, Yusuke Shomura, Kenichi Yoshida · 2010
Recently, the variety and vastness in networks have increased rapidly. To keep networks stable and reliable, network administrators have to understand the nature of network traffic flows. In this paper, we propose a method to analyze network traffic using firewall logs. The characteristics of our method are 1) the use of the aggregate flow information, and 2) the use of cardinality information of aggregate flows. Here, the cardinality information shows the number of servers/clients, and contributes to finding P2P software and Intranet viruses. The experimental results confirm that the session level cardinality information acquired by the proposed method can find P2P software and other types of applications.