Back to Search Start Over

ENTRADA: A high-performance network traffic data streaming warehouse

Authors :
Giovane C. M. Moura
Moritz Müller
Maarten Wullink
Cristian Hesselman
Source :
NOMS
Publication Year :
2016
Publisher :
IEEE, 2016.

Abstract

We present ENTRADA, a high-performance data streaming warehouse that enables researchers and operators to analyze vast amounts of network traffic and measurement data within interactive response times (seconds to few minutes), even in a small computer cluster. ENTRADA delivers such performance by employing a optimized file format and a high-performance query engine, both open-source. ENTRADA has been operational for more than 1.5 years, having ingested more than 100 TB of pcap files from two .nl DNS authoritative servers. As we discuss, we use this data in projects that aim at further increasing the security and stability of the .nl zone. We present in this paper our design choices, experiences, and a performance evaluation of ENTRADA. Finally, we open-source ENTRADA, which can be used “out-of-the-box” by researchers, operators, and registries to deploy their own networking analysis clusters for DNS traffic, and can be easily extended to handle any other structured data.

Details

Database :
OpenAIRE
Journal :
NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
Accession number :
edsair.doi...........e27d036bed4d11e1239cd49e0f3f1a3a
Full Text :
https://doi.org/10.1109/noms.2016.7502925