Selective Capping of Packet Payloads for Network Analysis and Management - Traffic Monitoring and Analysis Access content directly
Conference Papers Year : 2015

Selective Capping of Packet Payloads for Network Analysis and Management

Víctor Uceda
  • Function : Author
  • PersonId : 995497
Miguel Rodríguez
  • Function : Author
  • PersonId : 995498
Javier Ramos
  • Function : Author
  • PersonId : 995499
José Luis García-Dorado
  • Function : Author
  • PersonId : 995500
Javier Aracil
  • Function : Author
  • PersonId : 995501

Abstract

Both network managers and analysts appreciate the importance of network traces as a mechanism to understand traffic behavior, detect anomalies and evaluate performance in a forensic manner, among other applications. Unfortunately, the process of network capture and storage has become a challenge given the ever-increasing network speeds. In this scenario, we intend to make packets thinner to reduce both write speed and storage requirements on hard-drives and further reduce computational burden of packet analysis. To this end, we propose to remove the payload on those packets that hardly could be interpreted afterwards. Essentially, binary packets from unknown protocols fall into this category. On the other hand, binary packets from well-known protocols and protocols with some ASCII data are fully captured as potentially a network analyst may desire to inspect them. We have named this approach as selective capping, which has been implemented and integrated in a high-speed network driver as an attempt to make its operation faster and more transparent to upper layers. Its results are promising as it achieves multi-Gb/s rates in different scenarios, which could be further improved exploiting novel low-level hardware-software tunings to meet the fastest networks’ rates.
Fichier principal
Vignette du fichier
336978_1_En_1_Chapter.pdf (363.16 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01411176 , version 1 (07-12-2016)

Licence

Attribution

Identifiers

Cite

Víctor Uceda, Miguel Rodríguez, Javier Ramos, José Luis García-Dorado, Javier Aracil. Selective Capping of Packet Payloads for Network Analysis and Management. 7th Workshop on Traffic Monitoring and Analysis (TMA), Apr 2015, Barcelona, Spain. pp.3-16, ⟨10.1007/978-3-319-17172-2_1⟩. ⟨hal-01411176⟩
37 View
69 Download

Altmetric

Share

Gmail Facebook X LinkedIn More