ANTI: An Adaptive Network Traffic Indexing Algorithm for High-speed Networks

被引:0
|
作者
Chen, Jiale [1 ,2 ]
Chen, Xingshu [1 ,2 ,3 ]
Chen, Liangguo [1 ,2 ]
Lan, Xiao [2 ,3 ]
Luo, Yonggang [2 ,3 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu, Peoples R China
[2] Sichuan Univ, Key Lab Data Protect & Intelligent Management, Minist Educ, Chengdu, Peoples R China
[3] Sichuan Univ, Cyber Sci Res Inst, Chengdu, Peoples R China
基金
中国国家自然科学基金;
关键词
network traces; packet archiving; packet indexing; packet retrieval; radix tree;
D O I
10.1109/GLOBECOM54140.2023.10437924
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Network packets record communication behaviors and details, which is important for security audits, attack detection, and forensic analysis. For the effectiveness and timeliness of security analysis, it is necessary to fully store network packets and build an efficient packet index. However, the existing packet indexing algorithms based on the radix tree ignore the distribution characteristics of network traffic and use internal nodes with the same capacity for index construction, resulting in wasted disk space and poor retrieval performance. As a solution, we propose ANTI, an adaptive network traffic indexing algorithm similar to Adaptive Radix Tree, which can adaptively switch internal nodes with different capacity according to the density of network traffic and compress the common prefix and distinct suffix of traffic attributes to balance the index construction performance and space utilization. We also implement a packet-aware network traffic archiving and indexing system to achieve full packet archival, efficient indexing, and fast retrieval. Finally, we empirically evaluate ANTI in IPv4 (IPv6) traffic scenarios, and the results confirm the effectiveness of ANTI as well as the benefit of adopting ANTI for enhancing indexing and retrieval performance compared with other state-of-art algorithms.
引用
收藏
页码:1699 / 1704
页数:6
相关论文
共 50 条
  • [41] High-speed adaptive wireless body area networks
    Sudjai, Miftadi
    Le Chung Tran
    Safaei, Farzad
    Wysocki, Tadeusz
    Son Lam Phung
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2016,
  • [42] Adaptive configuration of elastic high-speed multiclass networks
    Yan, J
    IEEE COMMUNICATIONS MAGAZINE, 1998, 36 (05) : 116 - 120
  • [43] An adaptive strategy for high-speed network flow compression
    Wang, JF
    Li, L
    Zhou, MT
    Xu, FJ
    Sun, FC
    GLOBECOM '04: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6, 2004, : 1645 - 1649
  • [44] REAL-TIME TRAFFIC MEASUREMENTS FOR HIGH-SPEED NETWORKS
    HERSHEY, PC
    SILIO, CB
    WACLAWSKY, JG
    BT TECHNOLOGY JOURNAL, 1995, 13 (03): : 113 - 122
  • [45] CHARACTERIZATION OF THE TRAFFIC ON HIGH-SPEED TOKEN-RING NETWORKS
    SPIEGEL, EM
    BISDIKIAN, C
    TANTAWI, AN
    PERFORMANCE EVALUATION, 1994, 19 (01) : 47 - 72
  • [46] Dimensioning bandwidth for elastic traffic in high-speed data networks
    Berger, AW
    Kogan, Y
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2000, 8 (05) : 643 - 654
  • [47] LOTIC: A General Framework for High-Speed Network Traffic Processing
    Guo Haoran
    Li Haiyan
    Hao Liyun
    2019 IEEE 4TH INTERNATIONAL CONFERENCE ON SIGNAL AND IMAGE PROCESSING (ICSIP 2019), 2019, : 453 - 458
  • [48] Threshold-crossing analysis of high-speed network traffic
    Liu, JK
    Liu, XG
    Zhao, ZG
    Shu, YT
    CCECE 2003: CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING, VOLS 1-3, PROCEEDINGS: TOWARD A CARING AND HUMANE TECHNOLOGY, 2003, : 915 - 918
  • [49] Is high-speed wireless network traffic self-similar?
    Yu, B
    Petropulu, AP
    2004 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, VOL II, PROCEEDINGS: SENSOR ARRAY AND MULTICHANNEL SIGNAL PROCESSING SIGNAL PROCESSING THEORY AND METHODS, 2004, : 425 - 428
  • [50] Traffic behavior analysis with poisson sampling on high-speed network
    Cheng, G
    Gong, J
    2001 INTERNATIONAL CONFERENCES ON INFO-TECH AND INFO-NET PROCEEDINGS, CONFERENCE A-G: INFO-TECH & INFO-NET: A KEY TO BETTER LIFE, 2001, : E158 - E163