Analysis of traffic traces for stateful applications

Mateo Valero, Jorge Garcı́a-Vidal, Javier Verdú, Mario Nemirovsky · Dialnet (Universidad de la Rioja) · 2004

Traffic traces are important for many kinds of network research. For reasons of confidentiality, however, publicly available traffic traces are normally anonymized. This stripping of information discards vital properties of the captured traffic, rendering the traces unusable for certain network studies. Stateful networking applications are an emerging class of applications in the Network Processors area. The packet processing procedure for this class of applications differs significantly from that for stateless applications; thus, different sets of traffic properties are required for representative packet trace analysis. In this paper we study the differences in results between analysis based on sanitized traces and real traces processed by Snort, as an example of a stateful networking application. Our results demonstrate that there is, in fact, no significant difference. In addition, we analyze the impact of flow locality on the memory workload generated by Snort processing.

Read the paper · More papers on PaperTik