Proceedings of the Institute for System Programming of the RAS
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Proceedings of ISP RAS:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Proceedings of the Institute for System Programming of the RAS, 2015, Volume 27, Issue 4, Pages 5–22
DOI: https://doi.org/10.15514/ISPRAS-2015-27(4)-1
(Mi tisp161)
 

This article is cited in 2 scientific papers (total in 2 papers)

Model of data handling for in-depth analysis of network traffic

A. I. Get'mana, V. P. Ivannikovbacd, Yu. V. Markina, V. A. Padaryanac, A. Yu. Tikhonova

a Institute for System Programming of the Russian Academy of Sciences
b Moscow Institute of Physics and Technology
c Lomonosov Moscow State University
d Higher School of Economics, National Research University
Full-text PDF (326 kB) Citations (2)
References:
Abstract: The article suggests a new object model of data for in-depth analysis of network traffic. In contrast to the model used by most existing network analyzers, such as Wireshark or Snort, the core of our model supports data streams reassembling and next processing of them. Analysis continues even in case of loss of individual packets. The model supports both stateless and statefull network protocols. State of protocol machine may be stored in a special memory location related to each connection of relevant type. The article stated the requirements for network traffic analysis tools. A high speed data processing in resource-limited environment is the main requirement for online systems. Offline analyzer operates with a network trace of the fixed size, so the processing speed is not so important. It becomes possible to visualize the data structure disassembled. Offline analyzer also traces how network streams formed from packets. The model provides an interface for parsers implemented in the form of dynamic link libraries. It also provides a convenient universal mechanism for binding parsers so one can develop parsers independently. This is achieved through the use of special functions (recognizers) allowing for the data itself to determine which parser should be used. It is crucial for parsers to be compatible with both online and offline analyzers. Our model also provides processing of modified, e.g. compressed or encrypted, data. Unlike Snort the model supports nested tunneling protocols. Actually it forms the basis of the infrastructure for in-depth analysis of network traffic.
Keywords: network traffic analysis, data stream assembling, model of data, recognition of data.
Funding agency Grant number
Russian Foundation for Basic Research 15-07-07652
This work is supported by RFBR grant 15-07-07652 А
Bibliographic databases:
Document Type: Article
Language: Russian
Citation: A. I. Get'man, V. P. Ivannikov, Yu. V. Markin, V. A. Padaryan, A. Yu. Tikhonov, “Model of data handling for in-depth analysis of network traffic”, Proceedings of ISP RAS, 27:4 (2015), 5–22
Citation in format AMSBIB
\Bibitem{GetIvaMar15}
\by A.~I.~Get'man, V.~P.~Ivannikov, Yu.~V.~Markin, V.~A.~Padaryan, A.~Yu.~Tikhonov
\paper Model of data handling for in-depth analysis of network traffic
\jour Proceedings of ISP RAS
\yr 2015
\vol 27
\issue 4
\pages 5--22
\mathnet{http://mi.mathnet.ru/tisp161}
\crossref{https://doi.org/10.15514/ISPRAS-2015-27(4)-1}
\elib{https://elibrary.ru/item.asp?id=24928720}
Linking options:
  • https://www.mathnet.ru/eng/tisp161
  • https://www.mathnet.ru/eng/tisp/v27/i4/p5
  • This publication is cited in the following 2 articles:
    Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Proceedings of the Institute for System Programming of the RAS
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2025