【24h】

Long Term Data Storage Issues for Situational Awareness

机译:情境意识的长期数据存储问题

获取原文

摘要

Network traffic archives are useful for a number of purposes ranging from forensic studies to retrospective studies of the evolution of network traffic characteristics. The sheer volume of data that might be useful, if retained, imposes stresses on data storage and management systems. This is exacerbated by the fact that a substantial portion of network traffic is essentially noise and is interesting primarily at an aggregate level as the archive ages, while the remainder may remain interesting at the packet or flow level for an indefinite period. This paper discusses two cases, high volume scans and very infrequent traffic, where lossy compression may be applied to make substantial reductions in the volume of data retained while minimizing the risk of loosing interesting records. In addition, it discusses data structures, based of space and time efficient hashing methods that can be used to index network data using very large, sparse, index spaces such as those presented by IPv6 or by connection tuples that contain multiple IP addresses, along with service and protocol information.
机译:网络流量存档可用于许多目的,从法医研究到网络流量特征演变的回顾性研究。如果保留的话,可能有用的庞大数据量会给数据存储和管理系统带来压力。由于很大一部分网络流量本质上是噪声,并且随着存档的老化而主要在聚合级别引起关注,而其余部分可能在数据包或流级别无限期保持关注,这一事实加剧了这一点。本文讨论了两种情况,即高容量扫描和非常不频繁的流量,在这种情况下,可以应用有损压缩来大幅度减少保留的数据量,同时最大程度地减少丢失有趣记录的风险。此外,它还讨论了基于空间和时间高效散列方法的数据结构,该方法可用于使用非常大的稀疏索引空间(例如由IPv6或包含多个IP地址的连接元组提供的索引空间)对网络数据进行索引,以及服务和协议信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号