Hypersparse Traffic Matrices from Suricata Network Flows using GraphBLAS

Michael Houle,Michael Jones,Dan Wallmeyer,Risa Brodeur,Justin Burr,Hayden Jananthan,Sam Merrell,Peter Michaleas,Anthony Perez,Andrew Prout,Jeremy Kepner
2024-09-19
Abstract:Hypersparse traffic matrices constructed from network packet source and destination addresses is a powerful tool for gaining insights into network traffic. SuiteSparse: GraphBLAS, an open source package or building, manipulating, and analyzing large hypersparse matrices, is one approach to constructing these traffic matrices. Suricata is a widely used open source network intrusion detection software package. This work demonstrates how Suricata network flow records can be used to efficiently construct hypersparse matrices using GraphBLAS.
Distributed, Parallel, and Cluster Computing
What problem does this paper attempt to address?