Title :
RRDtrace: Long-term Raw Network Traffic Recording using Fixed-size Storage
Author :
Papadogiannakis, Antonis ; Polychronakis, Michalis ; Markatos, Evangelos P.
Author_Institution :
Inst. of Comput. Sci., Found. for Res. & Technol.-Hellas, Heraklion, Greece
Abstract :
Recording raw network traffic for long-term periods can be extremely beneficial for a multitude of monitoring and security applications. However, storing all traffic of high volume networks is infeasible even for short-term periods due to the increased storage requirements. Traditional approaches for data reduction like aggregation and sampling either require knowing the traffic features of interest in advance, or reduce the traffic volume by selecting a representative set of packets uniformly over the collecting period. In this work we present RRDtrace, a technique for storing full-payload packets for arbitrary long periods using fixed-size storage. RRDtrace divides time into intervals and retains a larger number of packets for most recent intervals. As traffic ages, an aging daemon is responsible for dynamically reducing its storage space by keeping smaller representative groups of packets, adapting the sampling rate accordingly. We evaluate the accuracy of RRDtrace on inferring the flow size distribution, distribution of traffic among applications, and percentage of malicious population. Our results show that RRDtrace can accurately estimate these properties using the suitable sampling strategy, some of them for arbitrary long time and others only for a recent period.
Keywords :
computer network security; data reduction; digital storage; telecommunication traffic recording; RRDtrace; data reduction; fixed-size storage; flow size distribution; full-payload packets; long-term raw network traffic recording; sampling strategy; security; Accuracy; Aging; Measurement; Monitoring; Payloads; Resource management; Security; Passive network monitoring; RRD; network trace; traffic recording;
Conference_Titel :
Modeling, Analysis & Simulation of Computer and Telecommunication Systems (MASCOTS), 2010 IEEE International Symposium on
Conference_Location :
Miami Beach, FL
Print_ISBN :
978-1-4244-8181-1
DOI :
10.1109/MASCOTS.2010.19