Stock Image

High-speed indexing and archival of network measurement data

Francesco Fusco

Published by Shaker Verlag Nov 2012, 2012
ISBN 10: 3844014640 / ISBN 13: 9783844014648
New / Taschenbuch / Quantity Available: 2
From Agrios-Buch (Bergisch Gladbach, Germany)
Available From More Booksellers
View all  copies of this book
Add to basket
Price: £ 45.01
Convert Currency
Shipping: £ 8.87
From Germany to United Kingdom
Destination, Rates & Speeds

Save for Later

About the Book

Bibliographic Details

Title: High-speed indexing and archival of network ...

Publisher: Shaker Verlag Nov 2012

Publication Date: 2012

Binding: Taschenbuch

Book Condition: Neu


Neuware - The Internet has became a global IT infrastructure providing ubiquitously accessible, interactive, and secure services used by a large fraction of the global population. To meet users' expectations, network administrators require sophisticated monitoring infrastructures for detecting misconfiguration and faults, for measuring the performance, and for enabling timely reactions to security threats. Passive monitoring has rapidly become the de-facto monitoring approach for getting deep insights into the actual status of production networks. Nowadays networks rely on network probes, which are embedded in network equipments or deployed as special purpose monitoring devices, that constantly monitor important network aspects. Therefore, current monitoring infrastructures are able to create large volumes of monitoring data. Industrial and academic research mostly focused on the generation, collection, processing and analysis of network monitoring data streams with the primary goal of providing live views of diverse network aspects. These efforts have led to mature technologies for processing high-speed data streams in real-time. Nowadays, stream processing represents the foundation for the large majority of software and hardware based monitoring infrastructures deployed for operating current production networks. In a nutshell, the stream processing approach consists of applying a predefined set of queries to one or more data streams in a way that summaries of the data are continuously computed. This approach allows one to have a predefined set of information about the network streams without requiring the streams to be entirely recorded, hence the name single-pass analytics. Unfortunately, this also means that the information not captured by the current query set is lost forever. In many emerging contexts including, but not limited to, cyber-security, this trade-off is undesirable. In particular, large corporations, financial institutions and high-security data centers are increasingly interested in efficient solutions enabling the collection of exact data streams, and the expedient analysis of large-scale repositories of historical network measurements particularly in case of security breaches. Enabling long-term historical analysis of massive volumes of network monitoring data is required to enable forensics, anomaly detection, and information leakage analysis tasks. Advanced data collection systems are required to enable the archival of high-speed streams of network monitoring data and, most importantly, to enable fast explorations of large-scale repositories. Such systems have to support data archiving under extremely high-speed insertion rates and to produce archives still amenable to indexing and search. Current solutions that address the challenge of lossless storage of massive network monitoring data streams use off-the-shelf compression techniques, like GZIP and BZIP2. The main shortcoming of these solutions is that they do not offer efficient query processing, especially for queries targeting a small part of the dataset, as large data blocks are compressed and then retrieved using expensive decompression operations and serial scans of the archives. In this thesis, we first focus on the storage, indexing, and data querying of high-speed streams of network flow information and we propose an architecture built upon novel lossless indexing and compression algorithms carefully optimized for the network monitoring domain. The architecture is capable of compressing high-speed streams of network flow records in real-time while achieving higher compression ratios than popular general-purpose compressors, and, more importantly, produces compressed archives that support partial decompression. Then, we describe an indexing architecture for packet traces that has been integrated into libpcap, the de-facto reference library for accessing packet trace repositories. We make the following important contributions: (a) we propose a n. Bookseller Inventory # 9783844014648

Bookseller & Payment Information

Payment Methods

This bookseller accepts the following methods of payment:

  • American Express
  • Bank/Wire Transfer
  • Check
  • Invoice
  • MasterCard
  • PayPal
  • Visa

[Search this Seller's Books]

[List this Seller's Books]

[Ask Bookseller a Question]

Bookseller: Agrios-Buch
Address: Bergisch Gladbach, Germany

AbeBooks Bookseller Since: 11 January 2012
Bookseller Rating: 5-star rating

Terms of Sale:

Allgemeine Geschäftsbedingungen (

der Firma Agrios Buch- und Medienversand UG e.K. ,Geschäftsführer Ludwig Meier, De-Gasperi-Str. 8, 51469 Bergisch Gladbach nachstehend als Verkäufer bezeichnet.

§ 1 Allgemeines, Begriffsbestimmungen

(1) Der Verkäufer bietet unter dem Nutzernamen Agrios Buch unter der Plattform insbesondere Bücher an. Die folgenden Allgemeinen Geschäftsbedingungen (AGB) gelten für die Geschäftsbeziehung zwischen dem Verkäufer und dem Kunden in ihrer zum Ze...

[More Information]

Shipping Terms:

Der Versand ins Ausland findet IMMER mit DHL statt. Auch nach Österreich verschicken wir nur mit DHL! Daher Standardversand == Luftpost!

Detailed Seller Information