High speed network traffic capture and analysis고속 네트워크 트래픽 수집 및 분석

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 425
  • Download : 0
Network packet capture performs essential functions in network management such as attack analysis, network troubleshooting, and performance debugging. As the network bandwidth exceeds 10s of Gbps, the demand for scalable packet capture and retrieval is rapidly increasing. However, existing software-based packet capture systems neither provide high performance nor support flow-level indexing for fast query response. This would either prevent important packets from being stored or make it too slow to retrieve relevant flows. In this dissertation, I present FloSIS, a highly scalable, software-based flow storing and indexing system. FloSIS is characterized as the following three aspects. First, it exercises full parallelism in multiple CPU cores and disks at all stages of packet processing. Second, it constructs two-stage flow-level indexes, which helps minimize expensive disk access for user queries. It also stores the packets in the same flow at a contiguous disk location, which maximizes disk read throughput. Third, I optimize storage usage by flow-level content deduplication at real time. My evaluation shows that FloSIS on a dual octa-core CPU machine with 24 HDDs achieves 30 Gbps of zero-drop performance with real traffic, consuming only 0.25% of the space for indexing. I use FloSIS to analyze real network traffic of a public data center in South Korea, that offers cloud services for business enterprises. I capture the entire traffic of the data center for 20 hours and check packet and flow level communication characteristics. In addition, I confirm the application protocols to figure out the applications running in the data center. Finally, I show two network management cases, anomaly detection and SDN system-level simulation.
Advisors
Yi, Yungresearcher이융researcherPark, KyoungSooresearcher박경수researcher
Description
한국과학기술원 :전기및전자공학부,
Publisher
한국과학기술원
Issue Date
2016
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전기및전자공학부, 2016.8 ,[iv, 59 p. :]

Keywords

high-speed network system; parallel processing system; deduplication; data center; network traffic measurement; 고속 네트워크 시스템; 병렬 처리 시스템; 데이터 중복 제거; 데이터 센터; 네트워크 트래픽 측정

URI
http://hdl.handle.net/10203/222349
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=663187&flag=dissertation
Appears in Collection
EE-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0