2007
DOI: 10.1109/mascots.2007.28
|View full text |Cite
|
Sign up to set email alerts
|

Improving the Performance of Passive Network Monitoring Applications using Locality Buffering

Abstract: Abstract-In this paper, we present a novel approach for improving the performance of a large class of CPU and memory intensive passive network monitoring applications, such as intrusion detection systems, traffic characterization applications, and NetFlow export probes. Our approach, called locality buffering, reorders the captured packets by clustering packets with the same destination port, before they are delivered to the monitoring application, resulting to improved code and data locality, and consequently… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
9
0

Year Published

2009
2009
2022
2022

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 9 publications
(9 citation statements)
references
References 3 publications
0
9
0
Order By: Relevance
“…Papadogiannakis and others [22] show how to preserve cache locality for improving traffic analysis performance by means of traffic reordering.…”
Section: Related Workmentioning
confidence: 99%
“…Papadogiannakis and others [22] show how to preserve cache locality for improving traffic analysis performance by means of traffic reordering.…”
Section: Related Workmentioning
confidence: 99%
“…Server side can get full report about transmission medium such as number of packets, loss of packets, throughput, bandwidth, protocol type, delay time, source IP address, destination IP address, destination port address, and source port address. On other hands, passive monitor may be as a device that can be deploy only in one side (either on client side or on server side) [22]. It is used as packet sniffer to gather information in order to analyses or examine packets or flows to identify malicious activities.…”
Section: Data In Motionmentioning
confidence: 99%
“…Papadogiannakis et al [59] proposed a novel approach named Locality Buffering (LB) to improve the performance of network data collection. They found that the application code, data storage structure (e.g., hash table) and attack signatures of network monitoring system all have the locality property of memory access.…”
Section: C: Locality Buffering Based Data Collectionmentioning
confidence: 99%