Network traffic data is of paramount importance in fields such as network forensics and management optimization. However, traditional network traffic storage methods face challenges of high cost and low efficiency when dealing with high-speed network monitoring. Most of the existing work focuses on selective storage algorithms or traffic reduction techniques, yet still encountering issues with insufficient accuracy in encrypted traffic selection and low data reduction efficiency. To this end, we propose SeRed, a selective reduction method designed for efficient network traffic storage, which implements differentiated storage strategies based on the type of network traffic. SeRed designs a traffic selection scheme based on entropy and consecutive ASCII character detection, which accurately identifies encrypted flows for selective storage. Moreover, an aggregated redundancy elimination algorithm is employed to effectively reduce the space and time expense of storing unencrypted data. Experimental results based on a real campus network traffic dataset show that SeRed reduces the error ratio by 4.2% in terms of traffic selection accuracy compared to the existing algorithm. In terms of data reduction efficiency, it achieves a speed increase of approximately two-fold at the same compression ratio, demonstrating significant advantages over the state-of-the-art baseline.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SeRed: A Selective Reduction Method for Efficient Network Flow Storage

  • Jie Ren,
  • Tao Zhao,
  • Shuhui Chen

摘要

Network traffic data is of paramount importance in fields such as network forensics and management optimization. However, traditional network traffic storage methods face challenges of high cost and low efficiency when dealing with high-speed network monitoring. Most of the existing work focuses on selective storage algorithms or traffic reduction techniques, yet still encountering issues with insufficient accuracy in encrypted traffic selection and low data reduction efficiency. To this end, we propose SeRed, a selective reduction method designed for efficient network traffic storage, which implements differentiated storage strategies based on the type of network traffic. SeRed designs a traffic selection scheme based on entropy and consecutive ASCII character detection, which accurately identifies encrypted flows for selective storage. Moreover, an aggregated redundancy elimination algorithm is employed to effectively reduce the space and time expense of storing unencrypted data. Experimental results based on a real campus network traffic dataset show that SeRed reduces the error ratio by 4.2% in terms of traffic selection accuracy compared to the existing algorithm. In terms of data reduction efficiency, it achieves a speed increase of approximately two-fold at the same compression ratio, demonstrating significant advantages over the state-of-the-art baseline.