FloCon 2013 Archive
• Presentation
Publisher
Software Engineering Institute
Abstract
At FloCon 2013, organizers and participants focused on the challenges of "Analysis at Scale." In large network environments, flow data helps to provide a scalable way of seeing the big picture, as well as a streamlined platform for highlighting patterns of malicious behavior over time. More and more commercial tools and platforms are available for collecting and storing not only flow data, but large volumes of other data such as DNS information, packet capture, security logs, and incident reports. Participants discussed how to refine "big data" into knowledge, design methods for aggregated analyses at the network edge, and build systems for monitoring thousands or millions of assets at once.
This archive includes:
- A Distributed Network Security Analysis System Based on Apache Hadoop-Related Technologies, Bingdong Li, Jeff Springer, Mehmet Gunes, and George Bebis
- Analysis of Communication Patterns in Network Flows to Discover Application Intent, William Turkett
- Automated Malware Traffic Analysis for IPS Analysts with Scapy and dpkt in Python, Geoffrey Serrao
- Bro for Real-Time Large-Scale Understanding, Seth Hall
- Clairvoyant Squirrel: A Scalable Domain Name Classification System, John Munro and Jason Trost
- Considerations for Scan Detection Using Flow Data, John McHugh
- CyberV@R: A Model to Compute Dollar Value at Risk of Loss to Cyber Attack, James Ulrich
- Detecting Malware P2P Traffic Using Network Flow and DNS Analysis, John Jerrim
- Enhancing Network Situational Awareness Using DPI Enhanced IPFIX, Hari Kosaraju
- Flow Analysis Using MapReduce, Markus Deshon
- FlowViewer: Maintaining NASA’s Earth Science Traffic Situational Awareness, Joe Loiacono
- Identifying Network Traffic Activity Via Flow Sizes, Michael Collins
- Identifying Network Users Using Flow-Based Behavioral Fingerprinting, Vincent Berk and John Murphy
- Introduction to Anomaly Detection, Char Sample and George Jones
- Network Analysis with SiLK (2013), Ron Bandes
- Near Real-Time Multi-Source Flow Data Correlation, Carter Bullard
- Network Flow 2012: Year in Review, George Warnagiris
- Network Security Monitoring in Minutes, Doug Burks
- Presenting Mongoose A New Approach to Traffic Capture, Ron McLeod and Ashraf Abu Sharekh
- Scalable NetFlow Analysis with Hadoop, Yeonhee Lee and Youngseok Lee
- Scalable Stacked Index to Speed Access to Multi Terabyte NetFlow, Bruce Griffin
- Situational Awareness Metrics from Flow and Other Data Sources, Soumyo D. Moitra
- Statistical Analysis of Flow Data Using Python and Redis, Kevin Noble
- Taming Big Flow Data, Igor Balabine and Sasha Velednitsky
- The Limitations of Analysis at Scale, Timothy J. Shimeall
- Thinking Security (Keynote), Steven M. Bellovin
- Visualization: Where Are We Going?, Tim Ray
- Flocon 2013: Call for Papers
This content was created for a conference series or symposium and does not necessarily reflect the positions and views of the Software Engineering Institute.