Data representation model for in-depth analysis of network traffic


Citar

Texto integral

Acesso aberto Acesso aberto
Acesso é fechado Acesso está concedido
Acesso é fechado Somente assinantes

Resumo

This paper proposes a new object model of data for the in-depth analysis of network traffic. In contrast to the model used by most modern network analyzers (for example, Wireshark and Snort), the proposed model supports data stream reassembling with subsequent parsing. The model also provides a convenient universal mechanism for binding parsers, thus making it possible to develop completely independent parsers. Moreover, the proposed model allows processing modified—compressed or encrypted—data. This model forms the basis of the infrastructure for the in-depth analysis of network traffic.

Sobre autores

I. Get’man

Institute for System Programming

Autor responsável pela correspondência
Email: thorin@ispras.ru
Rússia, ul. Solzhenitsyna 25, Moscow, 109004

V. Ivannikov

Institute for System Programming; Moscow State University; Moscow Institute of Physics and Technology; National Research University Higher School of Economics

Email: thorin@ispras.ru
Rússia, ul. Solzhenitsyna 25, Moscow, 109004; Moscow, 119991; Institutskii per. 9, Dolgoprudnyi, Moscow oblast, 141700; ul. Myasnitskaya 20, Moscow, 101000

Yu. Markin

Institute for System Programming

Email: thorin@ispras.ru
Rússia, ul. Solzhenitsyna 25, Moscow, 109004

V. Padaryan

Institute for System Programming; Moscow State University

Email: thorin@ispras.ru
Rússia, ul. Solzhenitsyna 25, Moscow, 109004; Moscow, 119991

A. Tikhonov

Institute for System Programming

Email: thorin@ispras.ru
Rússia, ul. Solzhenitsyna 25, Moscow, 109004

Arquivos suplementares

Arquivos suplementares
Ação
1. JATS XML

Declaração de direitos autorais © Pleiades Publishing, Ltd., 2016