Flow-Data Gathering Using NetFlow Sensors for Fitting Malicious-Traffic Detection Models

The work

TitleFlow-Data Gathering Using NetFlow Sensors for Fitting Malicious-Traffic Detection Models
AuthorsAdrián Campazas-Vega; Ignacio Samuel Crespo-Martínez; Ángel Manuel Guerrero-Higueras; Camino Fernández-Llamas
Typearticle
Year2020
Citekeycampazas2020flowdata

Where it appeared

Published inSensors
PublisherMultidisciplinary Digital Publishing Institute
Volume20
Issue24
Pages7294

Identifiers

DOI10.3390/s20247294
OpenAlexW3110894687

Access

Landing pagehttps://doi.org/10.3390/s20247294
Free full texthttps://www.mdpi.com/1424-8220/20/24/7294/pdf?version=1608535179
Link it arrived withhttps://www.mdpi.com/1424-8220/20/24/7294

Abstract

Advanced persistent threats (APTs) are a growing concern in cybersecurity. Many companies and governments have reported incidents related to these threats. Throughout the life cycle of an APT, one of the most commonly used techniques for gaining access is network attacks. Tools based on machine learning are effective in detecting these attacks. However, researchers usually have problems with finding suitable datasets for fitting their models. The problem is even harder when flow data are required. In this paper, we describe a framework to gather flow datasets using a NetFlow sensor. We also present the Docker-based framework for gathering netflow data (DOROTHEA), a Docker-based solution implementing the above framework. This tool aims to easily generate taggable network traffic to build suitable datasets for fitting classification models. In order to demonstrate that datasets gathered with DOROTHEA can be used for fitting classification models for malicious-traffic detection, several models were built using the model evaluator (MoEv), a general-purpose tool for training machine-learning algorithms. After carrying out the experiments, four models obtained detection rates higher than 93%, thus demonstrating the validity of the datasets gathered with the tool.

Copy held

KindPDF, 689.2 kB
Retrieved2026-08-10
Heldlocal, for personal reference
Where it came fromhttps://www.mdpi.com/1424-8220/20/24/7294/pdf?version=1608535179

Where this came from

How it got herethe agent went looking · found via openalex
First seen2026-08-07
Recordreviewed by a person
Approved2026-08-14

Cite it as

@article{campazas2020flowdata,
  title = {Flow-Data Gathering Using NetFlow Sensors for Fitting Malicious-Traffic Detection Models},
  author = {Adrián Campazas-Vega and Ignacio Samuel Crespo-Martínez and Ángel Manuel Guerrero-Higueras and Camino Fernández-Llamas},
  year = {2020},
  journal = {Sensors},
  volume = {20},
  number = {24},
  pages = {7294},
  publisher = {Multidisciplinary Digital Publishing Institute},
  doi = {10.3390/s20247294},
  url = {https://www.mdpi.com/1424-8220/20/24/7294/pdf?version=1608535179},
}

This record lives at https://refs.drheap.org/campazas2020flowdata/ and will keep doing so.