Protecting Research Networks with Rapidly Scalable Network Security Monitoring
Higher education research networks face unique security challenges: high-volume traffic, specialized protocols, limited budgets, and the need to balance openness with risk management. Traditional appliance-based monitoring approaches often struggle to scale or adapt to these environments.Through the NSF-funded MISTRAL (Massive Internal System Traffic Research Analysis and Logging) project, Duke University developed a rapidly scalable, cost-effective network security monitoring architecture using lightweight commodity hardware, containerized open-source tools, and automated deployment pipelines. This session will describe the MISTRAL architecture, including its sensor hardware, containerized monitoring stack, and novel use of Software Defined Networking and single root input/output virtualization (SR-IOV) passthrough to efficiently distribute traffic across multiple analysis tools without costly packet duplication. Attendees will learn how this approach improved visibility into research lab environments, reduced operational overhead, and enabled the creation of privacy-preserving network flow datasets for baselining, detection engineering, and AI/ML research. The session will share performance benchmarks, operational lessons learned, and free, publicly available resources that organizations can adapt to their own research and campus network environments.
Presenters
-
Alex Merck
IT Security Architect,
Duke University