The Experts below are selected from a list of 9258 Experts worldwide ranked by ideXlab platform
Evangelos P Markatos - One of the best experts on this subject based on the ideXlab platform.
-
stream oriented Network Traffic Capture and analysis for high speed Networks
IEEE Journal on Selected Areas in Communications, 2014Co-Authors: Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P MarkatosAbstract:Intrusion detection, Traffic classification, and other Network monitoring applications need to analyze the Captured Traffic beyond the Network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. Existing Network Traffic Capture frameworks, however, provide applications with raw packets and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap, between what applications need and what systems provide, leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet Capture subsystem and the stream processing module. This paper presents the Stream Capture library (Scap), a Network monitoring framework built from the ground up for stream-oriented Traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting Traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern Network cards. Our experimental evaluation shows that Scap can Capture all streams for Traffic rates two times higher than other stream reassembly libraries. Finally, we present the implementation and performance evaluation of four popular Network Traffic monitoring applications built on top of Scap.
-
scap stream oriented Network Traffic Capture and analysis for high speed Networks
Internet Measurement Conference, 2013Co-Authors: Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P MarkatosAbstract:Many Network monitoring applications must analyze Traffic beyond the Network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. However, existing Network Traffic Capture frameworks provide applications with just raw packets, and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet Capture subsystem and the stream processing module. This paper presents the Stream Capture library (Scap), a Network monitoring framework built from the ground up for stream-oriented Traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting Traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern Network cards. Our experimental evaluation shows that Scap can Capture all streams for Traffic rates two times higher than other stream reassembly libraries, and can process more than five times higher Traffic loads when eight cores are used for parallel stream processing in a pattern matching application.
Antonis Papadogiannakis - One of the best experts on this subject based on the ideXlab platform.
-
stream oriented Network Traffic Capture and analysis for high speed Networks
IEEE Journal on Selected Areas in Communications, 2014Co-Authors: Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P MarkatosAbstract:Intrusion detection, Traffic classification, and other Network monitoring applications need to analyze the Captured Traffic beyond the Network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. Existing Network Traffic Capture frameworks, however, provide applications with raw packets and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap, between what applications need and what systems provide, leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet Capture subsystem and the stream processing module. This paper presents the Stream Capture library (Scap), a Network monitoring framework built from the ground up for stream-oriented Traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting Traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern Network cards. Our experimental evaluation shows that Scap can Capture all streams for Traffic rates two times higher than other stream reassembly libraries. Finally, we present the implementation and performance evaluation of four popular Network Traffic monitoring applications built on top of Scap.
-
scap stream oriented Network Traffic Capture and analysis for high speed Networks
Internet Measurement Conference, 2013Co-Authors: Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P MarkatosAbstract:Many Network monitoring applications must analyze Traffic beyond the Network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. However, existing Network Traffic Capture frameworks provide applications with just raw packets, and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet Capture subsystem and the stream processing module. This paper presents the Stream Capture library (Scap), a Network monitoring framework built from the ground up for stream-oriented Traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting Traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern Network cards. Our experimental evaluation shows that Scap can Capture all streams for Traffic rates two times higher than other stream reassembly libraries, and can process more than five times higher Traffic loads when eight cores are used for parallel stream processing in a pattern matching application.
Michalis Polychronakis - One of the best experts on this subject based on the ideXlab platform.
-
stream oriented Network Traffic Capture and analysis for high speed Networks
IEEE Journal on Selected Areas in Communications, 2014Co-Authors: Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P MarkatosAbstract:Intrusion detection, Traffic classification, and other Network monitoring applications need to analyze the Captured Traffic beyond the Network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. Existing Network Traffic Capture frameworks, however, provide applications with raw packets and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap, between what applications need and what systems provide, leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet Capture subsystem and the stream processing module. This paper presents the Stream Capture library (Scap), a Network monitoring framework built from the ground up for stream-oriented Traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting Traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern Network cards. Our experimental evaluation shows that Scap can Capture all streams for Traffic rates two times higher than other stream reassembly libraries. Finally, we present the implementation and performance evaluation of four popular Network Traffic monitoring applications built on top of Scap.
-
scap stream oriented Network Traffic Capture and analysis for high speed Networks
Internet Measurement Conference, 2013Co-Authors: Antonis Papadogiannakis, Michalis Polychronakis, Evangelos P MarkatosAbstract:Many Network monitoring applications must analyze Traffic beyond the Network layer to allow for connection-oriented analysis, and achieve resilience to evasion attempts based on TCP segmentation. However, existing Network Traffic Capture frameworks provide applications with just raw packets, and leave complex operations like flow tracking and TCP stream reassembly to application developers. This gap leads to increased application complexity, longer development time, and most importantly, reduced performance due to excessive data copies between the packet Capture subsystem and the stream processing module. This paper presents the Stream Capture library (Scap), a Network monitoring framework built from the ground up for stream-oriented Traffic processing. Based on a kernel module that directly handles flow tracking and TCP stream reassembly, Scap delivers to user-level applications flow-level statistics and reassembled streams by minimizing data movement operations and discarding uninteresting Traffic at early stages, while it inherently supports parallel processing on multi-core architectures, and uses advanced capabilities of modern Network cards. Our experimental evaluation shows that Scap can Capture all streams for Traffic rates two times higher than other stream reassembly libraries, and can process more than five times higher Traffic loads when eight cores are used for parallel stream processing in a pattern matching application.
Y. Beeharry - One of the best experts on this subject based on the ideXlab platform.
-
Performance analysis of Network Traffic Capture tools and machine learning algorithms for the classification of applications, states and anomalies
International Journal of Information Technology, 2020Co-Authors: T. P. Fowdur, B. N. Baulum, Y. BeeharryAbstract:Network analytics is of key importance for the proper management of Network resources as the rate of Internet Traffic continues to rise. The aim of this paper is to investigate the performance of different Network Traffic Capture tools for extracting features and to evaluate the performance of eight Machine Learning (ML) algorithms in the classification of (1) applications; (2) states and (3) anomalies. Six Internet applications were considered along with four PC states and two Network anomalies. The Network was monitored by three Traffic Capture tools: PRTG, Colasoft Capsa and Wireshark and classification was performed using the Weka Toolkit. The performance of the eight ML classifiers was determined based on several metrics. The Colasoft Capsa feature set gave the highest accuracy for the classification of applications while same was achieved with features from PRTG for the classification of the four states considered. For anomaly classification, the ML algorithms showed almost similar classification behavior when the Colasoft Capsa or PRTG feature set was used.
T. P. Fowdur - One of the best experts on this subject based on the ideXlab platform.
-
Performance analysis of Network Traffic Capture tools and machine learning algorithms for the classification of applications, states and anomalies
International Journal of Information Technology, 2020Co-Authors: T. P. Fowdur, B. N. Baulum, Y. BeeharryAbstract:Network analytics is of key importance for the proper management of Network resources as the rate of Internet Traffic continues to rise. The aim of this paper is to investigate the performance of different Network Traffic Capture tools for extracting features and to evaluate the performance of eight Machine Learning (ML) algorithms in the classification of (1) applications; (2) states and (3) anomalies. Six Internet applications were considered along with four PC states and two Network anomalies. The Network was monitored by three Traffic Capture tools: PRTG, Colasoft Capsa and Wireshark and classification was performed using the Weka Toolkit. The performance of the eight ML classifiers was determined based on several metrics. The Colasoft Capsa feature set gave the highest accuracy for the classification of applications while same was achieved with features from PRTG for the classification of the four states considered. For anomaly classification, the ML algorithms showed almost similar classification behavior when the Colasoft Capsa or PRTG feature set was used.