Research Article

Efficient Extraction of Network Event Types from NetFlows

Figure 2

Language of formulae checking values of features assembled from sets of flows. The individual flows can be grouped by some of their attributes while their other attributes are further aggregated using some of the listed aggregation functions. This aggregation process might be repeated in a recursive manner. A final derived feature is subsequently checked against a membership function of the enumeration of values or intervals to find whether the respective formula holds true. Arrows represent aggregated combinations in use by formulae of actual event types in use.