@techreport{fu-ipfix-network-security-01, number = {draft-fu-ipfix-network-security-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-fu-ipfix-network-security/01/}, author = {Tianfu Fu and Dacheng Zhang and ana.hedanping@huawei.com and Liang Xia}, title = {{IPFIX Information Elements for inspecting network security issues}}, pagetotal = 14, year = 2015, month = apr, day = 28, abstract = {IPFIX protocol has been used to carry Information Elements, which are defined to measure the traffic information and information related to the traffic observation point, traffic metering process and the exporting process. Network or device status are checked through analysing neccessary observed information. Although most of the existing Information Elements are useful for network security inspection, they are still not sufficient to determine the reasons behind observed events such as for DDOS attack, ICMP attack, and fragment attack. To allow administrators making effective and quick response to the attacks, this document extends the standard Information Elements and describes the formats for inspecting network security.}, }