首页> 外文会议>Information and communication technology >Aggregation of Network Protocol Data Near Its Source
【24h】

Aggregation of Network Protocol Data Near Its Source

机译:源附近的网络协议数据聚合

获取原文
获取原文并翻译 | 示例

摘要

In Network Anomaly and Botnet Detection the main source of input for analysis is the network traffic, which has to be transmitted from its capture source to the analysis system. High-volume data sources often generate traffic volumes prohibiting direct pass-through of bulk data into researchers hands. In this paper we achieve a reduction in volume of transmitted test data from network flow captures by aggregating raw data using extraction of protocol semantics. This is orthogonal to classic bulk compression algorithms. We propose a formalization for this concept called Descriptors and extend it to network flow data. A comparison with common bulk data file compression formats will be given for full Packet Capture (PCAP) files, giving 4 to 5 orders of magnitude in size reduction using Descriptors. Our approach aims to be compatible with Internet Protocol Flow Information Export (IPFIX) and other standardized network flow data formats as possible inputs.
机译:在网络异常和僵尸网络检测中,用于分析的主要输入源是网络流量,必须将其从捕获源传输到分析系统。大量数据源经常产生流量,从而禁止将大量数据直接传递到研究人员的手中。在本文中,我们通过使用协议语义提取来聚合原始数据,从而减少了从网络流捕获中传输的测试数据的数量。这与经典的批量压缩算法正交。我们建议将此概念称为“描述符”的形式化并将其扩展到网络流数据。对于完整的数据包捕获(PCAP)文件,将与常见的批量数据文件压缩格式进行比较,使用描述符将大小减小4至5个数量级。我们的方法旨在与Internet协议流信息导出(IPFIX)和其他标准化的网络流数据格式兼容,以作为可能的输入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号