Show simple item record

Authordc.contributor.authorKim, Young-Hwan 
Authordc.contributor.authorKonow, Roberto 
Authordc.contributor.authorDujovne, Diego 
Authordc.contributor.authorTurletti, Thierry 
Authordc.contributor.authorDabbous, Walid 
Authordc.contributor.authorNavarro, Gonzalo 
Admission datedc.date.accessioned2015-07-15T13:24:23Z
Available datedc.date.available2015-07-15T13:24:23Z
Publication datedc.date.issued2015
Cita de ítemdc.identifier.citationComputer Networks 79 (2015) 91–102en_US
Identifierdc.identifier.urihttps://repositorio.uchile.cl/handle/2250/131975
Abstractdc.description.abstractNetwork packet tracing has been used for many different purposes during the last few decades, such as network software debugging, networking performance analysis, forensic investigation, and so on. Meanwhile, the size of packet traces becomes larger, as the speed of network rapidly increases. Thus, to handle huge amounts of traces, we need not only more hardware resources, but also efficient software tools. However, traditional tools are inefficient at dealing with such big packet traces. In this paper, we propose pcapWT, an efficient packet extraction tool for large traces. PcapWT provides fast packet lookup by indexing an original trace using a wavelet tree structure. In addition, pcapWT supports multi-threading for avoiding synchronous I/O and blocking system calls used for file processing, and is particularly efficient on machines with SSD. PcapWT shows remarkable performance enhancements in comparison with traditional tools such as tcpdump and most recent tools such as pcapIndex in terms of index data size and packet extraction time. Our benchmark using large and complex traces shows that pcapWT reduces the index data size down below 1% of the volume of the original traces. Moreover, packet extraction performance is 20% better than with pcapIndex. Furthermore, when a small amount of packets are retrieved, pcapWT is hundreds of times faster than tcpdump.en_US
Lenguagedc.language.isoenen_US
Publisherdc.publisherElsevieren_US
Type of licensedc.rightsAtribución-NoComercial-SinDerivadas 3.0 Chile*
Link to Licensedc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/cl/*
Keywordsdc.subjectNetwork tracesen_US
Keywordsdc.subjectPacket indexingen_US
Keywordsdc.subjectPacket extractionen_US
Keywordsdc.subjectWavelet treeen_US
Keywordsdc.subjectMulti-thread file I/Oen_US
Títulodc.titlePcapWT: An efficient packet extraction tool for large volume network tracesen_US
Document typedc.typeArtículo de revista


Files in this item

Icon

This item appears in the following Collection(s)

Show simple item record

Atribución-NoComercial-SinDerivadas 3.0 Chile
Except where otherwise noted, this item's license is described as Atribución-NoComercial-SinDerivadas 3.0 Chile