Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
research-article

pcapIndex: an index for network packet traces with legacy compatibility

Published: 16 January 2012 Publication History

Abstract

Long-term historical analysis of captured network traffic is a topic of great interest in network monitoring and network security. A critical requirement is the support for fast discovery of packets that satisfy certain criteria within large-scale packet repositories. This work presents the first indexing scheme for network packet traces based on compressed bitmap indexing principles. Our approach supports very fast insertion rates and results in compact index sizes. The proposed indexing methodology builds upon libpcap, the de-facto reference library for accessing packet-trace repositories. Our solution is therefore backward compatible with any solution that uses the original library. We experience impressive speedups on packet-trace search operations: our experiments suggest that the index-enabled libpcap may reduce the packet retrieval time by more than 1100 times.

References

[1]
Endace Measurement Systems. http://www.endace.com.
[2]
TCPDUMP/LIBPCAP public repository. http://www.tcpdump.org/.
[3]
E. W. Bethel, S. Campbell, E. Dart, K. Stockinger, and K. Wu. Accelerating Network Traffic Analysis Using Query-Driven Visualization. In Proc. of 2006 IEEE Symposium on Visual Analytics Science and Technology, pages 115--122, 2006.
[4]
F. Deliàge and T. B. Pedersen. Position list word aligned hybrid: optimizing space and performance for compressed bitmaps. In Proc. of the 13th Int. Conf. on Extending Database Technology, pages 228--239, 2010.
[5]
L. Deri, V. Lorenzetti, and S. Mortimer. Collection and Exploration of Large Data Monitoring Sets Using Bitmap Databases. In 2nd Int. Workshop on Traffic Monitoring and Analysis(TMA), pages 73--86, 2010.
[6]
P. J. Desnoyers and P. Shenoy. Hyperion: high volume stream archival for retrospective querying. In Proc. of the USENIX Annual Technical Conf., 2007.
[7]
F. Fusco, M. P. Stoecklin, and M. Vlachos. Net-fli: on-the-fly compression, archiving and indexing of streaming network traffic. Proc. VLDB Endow., 3, 2010.
[8]
C. R. Kalmanek et al. Darkstar: Using exploratory data mining to raise the bar on network reliability and performance. In 7th Int. Workshop on Design of Reliable Communication Networks, 2009.
[9]
G. Maier, R. Sommer, H. Dreger, A. Feldmann, V. Paxson, and F. Schneider. Enriching network security analysis with time travel. In Proc. of the ACM SIGCOMM 2008 Conf. on Data communication, pages 183--194, 2008.
[10]
S. McCanne and V. Jacobson. The BSD packet filter: a new architecture for user-level packet capture. In Proc. of the USENIX Winter Conf., pages 2--2, 1993.
[11]
K. Wu, E. Otoo, and A. Shoshani. On the Performance of Bitmap Indices for High Cardinality Attributes. In Proc. of the 13th Int. Conf. on Very Large Data Dases (VLDB), pages 24--35, 2004.
[12]
K. Wu, E. J. Otoo, and A. Shoshani. Optimizing bitmap indices with efficient compression. ACM Trans. Database Syst., 31:1--38, March 2006.

Cited By

View all
  • (2023)LiteEx: A Lightweight Feature Extraction Tool for Captured Network Traces2023 15th International Conference on COMmunication Systems & NETworkS (COMSNETS)10.1109/COMSNETS56262.2023.10041389(243-251)Online publication date: 3-Jan-2023
  • (2021)An Efficient Indexing Scheme for Network Traffic Collection and Retrieval SystemElectronics10.3390/electronics1002019110:2(191)Online publication date: 15-Jan-2021
  • (2021)Compact-indexProceedings of the 17th International Conference on emerging Networking EXperiments and Technologies10.1145/3485983.3494858(90-103)Online publication date: 2-Dec-2021
  • Show More Cited By

Index Terms

  1. pcapIndex: an index for network packet traces with legacy compatibility

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM SIGCOMM Computer Communication Review
    ACM SIGCOMM Computer Communication Review  Volume 42, Issue 1
    January 2012
    88 pages
    ISSN:0146-4833
    DOI:10.1145/2096149
    Issue’s Table of Contents

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 16 January 2012
    Published in SIGCOMM-CCR Volume 42, Issue 1

    Check for updates

    Author Tag

    1. packet indexing

    Qualifiers

    • Research-article

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • Downloads (Last 12 months)10
    • Downloads (Last 6 weeks)1
    Reflects downloads up to 09 Nov 2024

    Other Metrics

    Citations

    Cited By

    View all
    • (2023)LiteEx: A Lightweight Feature Extraction Tool for Captured Network Traces2023 15th International Conference on COMmunication Systems & NETworkS (COMSNETS)10.1109/COMSNETS56262.2023.10041389(243-251)Online publication date: 3-Jan-2023
    • (2021)An Efficient Indexing Scheme for Network Traffic Collection and Retrieval SystemElectronics10.3390/electronics1002019110:2(191)Online publication date: 15-Jan-2021
    • (2021)Compact-indexProceedings of the 17th International Conference on emerging Networking EXperiments and Technologies10.1145/3485983.3494858(90-103)Online publication date: 2-Dec-2021
    • (2019)A Survey on Big Data for Network Traffic Monitoring and AnalysisIEEE Transactions on Network and Service Management10.1109/TNSM.2019.293335816:3(800-813)Online publication date: Sep-2019
    • (2019)CompactFlow: A Hybrid Binary Format for Network Flow DataInformation Security Theory and Practice10.1007/978-3-030-41702-4_12(185-201)Online publication date: 11-Dec-2019
    • (2016)VASTProceedings of the 13th Usenix Conference on Networked Systems Design and Implementation10.5555/2930611.2930634(345-362)Online publication date: 16-Mar-2016
    • (2015)FloSISProceedings of the 2015 USENIX Conference on Usenix Annual Technical Conference10.5555/2813767.2813800(445-457)Online publication date: 8-Jul-2015
    • (2015)PcapWTComputer Networks: The International Journal of Computer and Telecommunications Networking10.1016/j.comnet.2014.12.00779:C(91-102)Online publication date: 14-Mar-2015
    • (2015)Performance Comparison of Relational Databases and Columnar Databases Using Bitmap Index for Fast Search of 10Gbps Network FlowsAdvances in Computer Science and Ubiquitous Computing10.1007/978-981-10-0281-6_25(171-175)Online publication date: 18-Dec-2015
    • (2013)Indexing million of packets per second using GPUsProceedings of the 2013 conference on Internet measurement conference10.1145/2504730.2504756(327-332)Online publication date: 23-Oct-2013
    • Show More Cited By

    View Options

    Get Access

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media