Back to Search Start Over

Aggregation of Network Protocol Data Near Its Source

Authors :
Kevin Stegemann
Norbert Pohlmann
Dominique Petersen
Marcel Fourné
Institute for Internet Security [Gelsenkirchen] (if(is))
David Hutchison
Takeo Kanade
Bernhard Steffen
Demetri Terzopoulos
Doug Tygar
Gerhard Weikum
Linawati
Made Sudiana Mahendra
Erich J. Neuhold
A Min Tjoa
Ilsun You
Josef Kittler
Jon M. Kleinberg
Alfred Kobsa
Friedemann Mattern
John C. Mitchell
Moni Naor
Oscar Nierstrasz
C. Pandu Rangan
TC 5
TC 8
Source :
Information and Communication Technology ISBN: 9783642550317, ICT-EurAsia, Lecture Notes in Computer Science, 2nd Information and Communication Technology-EurAsia Conference (ICT-EurAsia), 2nd Information and Communication Technology-EurAsia Conference (ICT-EurAsia), Apr 2014, Bali, Indonesia. pp.482-491, ⟨10.1007/978-3-642-55032-4_49⟩
Publication Year :
2014
Publisher :
Springer Berlin Heidelberg, 2014.

Abstract

Part 2: The 2014 Asian Conference on Availability, Reliability and Security, AsiaARES 2014; International audience; In Network Anomaly and Botnet Detection the main source of input for analysis is the network traffic, which has to be transmitted from its capture source to the analysis system. High-volume data sources often generate traffic volumes prohibiting direct pass-through of bulk data into researchers hands.In this paper we achieve a reduction in volume of transmitted test data from network flow captures by aggregating raw data using extraction of protocol semantics. This is orthogonal to classic bulk compression algorithms. We propose a formalization for this concept called Descriptors and extend it to network flow data.A comparison with common bulk data file compression formats will be given for full Packet Capture (PCAP) files, giving 4 to 5 orders of magnitude in size reduction using Descriptors.Our approach aims to be compatible with Internet Protocol Flow Information Export (IPFIX) and other standardized network flow data formats as possible inputs.

Details

ISBN :
978-3-642-55031-7
ISBNs :
9783642550317
Database :
OpenAIRE
Journal :
Information and Communication Technology ISBN: 9783642550317, ICT-EurAsia, Lecture Notes in Computer Science, 2nd Information and Communication Technology-EurAsia Conference (ICT-EurAsia), 2nd Information and Communication Technology-EurAsia Conference (ICT-EurAsia), Apr 2014, Bali, Indonesia. pp.482-491, ⟨10.1007/978-3-642-55032-4_49⟩
Accession number :
edsair.doi.dedup.....a94c1a45322d8f8bd8fd37de59729506
Full Text :
https://doi.org/10.1007/978-3-642-55032-4_49