Diplomová práce

Distributed Complex Event Processing for Network Security

Bc. Štefan Repček, učo 373862
Anotace

Cieľom tejto diplomovej práce je predstaviť aplikáciu, ktorá umožní vytvoriť architektúru pre Distribuovaný Complex Event Processing na monitorovanie sietí. Daná architektúra kombinuje prvky Complex Event Processing a Stream Processing s cieľom poskytnúť distribuované a škálovatelné riešenie vhodné na monitorovanie sietí. Vyvinutá aplikácia je použitá na vybudovanie distribuovanej architektúry na detekciu …více

Abstract

The aim of this master thesis is to introduce an application which allows to built an architecture for Distributed Complex Event Processing for network security monitoring. The architecture combines a state of the art Complex Event Processing and Stream Processing to provide a distributed, scalable and fault-tolerant solution suitable for network monitoring. The developed application is used to build …více

Zadání práce

The main goal of the master thesis is to introduce an architecture for Distributed Complex Event Processing for network security monitoring to address real time monitoring of IP flow records to be able to detect DDOS attacks. The solution will leverage Complex Event Processing within a IP flow monitoring approach.

Distributed nature means that event stream is being processed by multiple computers (nodes). Student will use open-source engine Esper for Complex Event Processing.

First part of the master thesis will consist of the design and implementation of a module to provide distributed architecture. Student will choose proper technologies to provide this functionality. This module will be independent which means that it is possible to integrate it with any data stream (not only with IP flow data).

In second part of the master thesis student will use this module to build architecture for detection of DDOS flooding attacks (SYN flood). Student will implement algorithm for detection of these types of attacks which will be leveraged within this architecture. Student will perform experiment using IP flow dataset to show that his designed distributed architecture is able to detect DDOS flooding attacks.

Práce zkontrolována:
12. 1. 2016 11:08, RNDr. Filip Nguyen, učo 208428
Plný text práce
1,1 MB / soubor PDF
Jazyk práce
angličtina angličtina
Termín obhajoby
17. 2. 2016
Práce byla úspěšně obhájena

Vedoucí

RNDr. Filip Nguyen, učo 208428
KPSK FI MU

Oponent

Radu State, Ph.D.

Masarykova univerzita Fakulta informatiky
Studijní program
Aplikovaná informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.