Enhancing performance of cardinality analysis by packet filtering
Enhancing performance of cardinality analysis by packet filtering
复制标题
DOI:
10.1109/icoin.2016.7427068
复制
发表时间:
2016-01
期刊:
影响因子:
--
通讯作者:
S. Mori;Akira Sato;K. Yoshida
中科院分区:
文献类型:
--
作者:
S. Mori;Akira Sato;K. Yoshida
Cardinality in network flow data gives useful information for network administrators about suspicious communication on their network. Such communication tends to present abnormal number of source and/or destination network address. Our research group reported that cardinality presented in TCP/IP packet header can be used to detect malware propagation and P2P software usage in small size network. However the processing speed of the cardinality analyzer is not enough to analyze high speed network line over 20Gbps. In this paper, we propose a technique to offload the analyzer by packet filtering based on the TCP flags. We also report the performance and the limitation of the proposed technique.