Research Article

Efficient Extraction of Network Event Types from NetFlows

Figure 4

Depiction of comparison of the new two staged event extraction method (right) with the actual one in Camnep (left). In the first stage, also called expansion of version space, the flow-specific formulae are being processed to create proto-events. In the second stage, referred to as the aggregation phase, the proto-events are processed through the aggregative formulae to produce output events.