Monitoring Networks with Insightful Queries
Quangtri Thai, CARLOS R. ORDÓÑEZ, Omprakash Gnawali · 2020
Monitoring networks requires efficiently detecting abnormal events and summarizing connection information in big volumes of packet-level data. Some of these tasks can be accomplished with network and operating system utilities, but questions should be relatively simple and data pre-processing should be kept at a minimum. Another requirement is to be able to process data, both in a centralized and decentralized manner given the dynamic nature of TCP-IP packet flow. On the other hand, database systems can answer complex questions phrased as queries, provided data is in the right format and is quickly loaded. Having such motivation in mind, we propose to monitor a network with queries, running on a traditional DBMS (i.e. not a custom-built system programmed in C or C++). Thus, queries can be processed in a central manner in a traditional database server or in a distributed fashion with edge computing. A brief experimental evaluation shows queries can indeed be used to monitor the network with low latency and reasonable delay.