IPFIX Information Elements for inspecting network security issues
2015
IPFIX protocol has been used to carry Information Elements, which are
defined to measure the traffic information and information related to
the traffic observation point, traffic metering process and the
exporting process. Network or device status are checked through
analysing neccessary observed information. Although most of the
existing Information Elements are useful for network security
inspection, they are still not sufficient to determine the reasons
behind observed events such as for DDOS attack, ICMP attack, and
fragment attack. To allow administrators making effective and quick
response to the attacks, this document extends the standard
Information Elements and describes the formats for inspecting network
security.
Keywords:
- Correction
- Source
- Cite
- Save
- Machine Reading By IdeaReader
0
References
0
Citations
NaN
KQI