Low-storage capture and loss recovery selective replay of real flows

Ying-Dar Lin*, Po Ching Lin, Tsung Huan Cheng, I. Wei Chen, Yuan Cheng Lai

*Corresponding author for this work

研究成果: Article同行評審

16 引文 斯高帕斯(Scopus)

摘要

Capturing and replaying real flows are important for testing network security products. However, capturing real flows demands a high storage cost and runs a risk of capture loss, which makes the replay inaccurate. Replaying real flows should be accurate and stateful to adapt to the reaction of the device under test. It should also efficiently reproduce a defect and help developers identify the flows triggering defects. Therefore, this work first presents the (N, M, P) capture scheme which begins with, for each connection, capturing at most N bytes of application payload and then at most M bytes of application payload for at most each of the subsequent P packets in the same connection. This scheme reduces 87 percent of storage cost while retaining 99.74 percent of original events. This work develops a tool named SocketReplay with the mechanisms of loss recovery, stateful replay, and selective replay. Loss recovery tracks TCP sequence numbers to identify capture loss and recovers incomplete flows with dummy data. Stateful replay maintains the states in the TCP/IP stack to replay real flows. Selective replay incrementally selects flows to replay. The results show that SocketReplay can accurately and efficiently reproduce product events and significantly decrease the volume of replayed packet traces.

原文English
文章編號6178843
頁(從 - 到)114-121
頁數8
期刊IEEE Communications Magazine
50
發行號4
DOIs
出版狀態Published - 1 四月 2012

指紋 深入研究「Low-storage capture and loss recovery selective replay of real flows」主題。共同形成了獨特的指紋。

引用此