Stream-Oriented Network Traffic Capture and Analysis for High-Speed Networks

被引:10
|
作者
Papadogiannakis, Antonis [1 ]
Polychronakis, Michalis [2 ]
Markatos, Evangelos P. [1 ]
机构
[1] Fdn Res & Technol Hellas, Inst Comp Sci, Iraklion 70013, Greece
[2] Columbia Univ, Dept Comp Sci, New York, NY 10027 USA
关键词
Traffic monitoring; stream reassembly; packet capture; packet filtering; overload control; performance; EFFICIENT; ATTACKS;
D O I
10.1109/JSAC.2014.2358831
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Intrusion detection, traffic classification, and other network monitoring applications need to analyze the captured traffic beyond the network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. Existing network traffic capture frameworks, however, provide applications with raw packets and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap, between what applications need and what systems provide, leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet capture subsystem and the stream processing module. This paper presents the Stream capture library (Scap), a network monitoring framework built from the ground up for stream-oriented traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern network cards. Our experimental evaluation shows that Scap can capture all streams for traffic rates two times higher than other stream reassembly libraries. Finally, we present the implementation and performance evaluation of four popular network traffic monitoring applications built on top of Scap.
引用
收藏
页码:1849 / 1863
页数:15
相关论文
共 50 条
  • [1] Bispectral analysis of traffic in high-speed networks
    Terdik, G
    Gál, Z
    Iglói, E
    Molnár, S
    [J]. COMPUTERS & MATHEMATICS WITH APPLICATIONS, 2002, 43 (12) : 1575 - 1583
  • [2] SONAR: A Scalable Stream-oriented System for Real-time Network Traffic Measurements
    Liu, Jun
    Du, Yutan
    Yang, Jie
    Ansari, Nirwan
    [J]. 2015 IEEE 16TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (HPSR), 2015, : 158 - 163
  • [3] High-speed network traffic
    Katsaggelos, AK
    [J]. IEEE SIGNAL PROCESSING MAGAZINE, 2002, 19 (03) : 2 - +
  • [4] Network traffic characterization for high-speed networks supporting multimedia
    Elleithy, KM
    Al-Suwaiyan, AS
    [J]. 34TH ANNUAL SIMULATION SYMPOSIUM, PROCEEDINGS, 2001, : 200 - 207
  • [5] TRAFFIC ENGINEERING FOR HIGH-SPEED NETWORKS
    KUHN, PJ
    [J]. IFIP TRANSACTIONS C-COMMUNICATION SYSTEMS, 1992, 5 : 7 - 25
  • [6] Stream-oriented Lossless Packet Compression in Wireless Sensor Networks
    Reinhardt, Andreas
    Hollick, Matthias
    Steinmetz, Ralf
    [J]. 2009 6TH ANNUAL IEEE COMMUNICATIONS SOCIETY CONFERENCE ON SENSOR, MESH AND AD HOC COMMUNICATIONS AND NETWORKS (SECON 2009), 2009, : 99 - 107
  • [7] High-speed network traffic model
    Shang, FJ
    Tang, H
    [J]. PROCEEDINGS OF THE THIRD INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION SCIENCE AND TECHNOLOGY, VOL 1, 2004, : 529 - 533
  • [8] Network intrusion detection systems in high-speed traffic in computer networks
    Bul'ajoul, Waleed
    James, Anne
    Pannu, Mandeep
    [J]. 2013 IEEE 10TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2013, : 168 - 175
  • [9] ANTI: An Adaptive Network Traffic Indexing Algorithm for High-speed Networks
    Chen, Jiale
    Chen, Xingshu
    Chen, Liangguo
    Lan, Xiao
    Luo, Yonggang
    [J]. IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 1699 - 1704
  • [10] Threshold-crossing analysis of high-speed network traffic
    Liu, JK
    Liu, XG
    Zhao, ZG
    Shu, YT
    [J]. CCECE 2003: CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-3, PROCEEDINGS: TOWARD A CARING AND HUMANE TECHNOLOGY, 2003, : 915 - 918