서브메뉴
검색
Practical Systems For Traffic Analysis on Modern Networks
Practical Systems For Traffic Analysis on Modern Networks
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20250211152116
- ISBN
- 9798384338048
- DDC
- 500
- 저자명
- Wan, Gerry.
- 서명/저자
- Practical Systems For Traffic Analysis on Modern Networks
- 발행사항
- [Sl] : Stanford University, 2024
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2024
- 형태사항
- 131 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 86-03, Section: A.
- 주기사항
- Advisor: Durumeric, Zakir.
- 학위논문주기
- Thesis (Ph.D.)--Stanford University, 2024.
- 초록/해제
- 요약Network traffic analysis is essential for understanding and securing production networks. It is routinely used by both operators and researchers to investigate network behaviors, identify security threats, and monitor performance. However, network traffic has grown increasingly opaque. The rise of end-to-end encryption and the rapid growth in network speeds have outpaced the capabilities of traditional analysis methods, hindering visibility into modern networks.Despite recent progress in the development of specialized tools for high-speed networks and machine learning (ML) techniques for analyzing encrypted traffic, such tools and techniques remain difficult to deploy in practice. Many systems built on advanced networking hardware are performant, but cannot accommodate complex analysis tasks involving reassembled or parsed network data. ML-based solutions can infer information from encrypted traffic but often do not meet the performance demands of running in real-world networks.Traffic analysis systems should be practical: versatile enough to enable diverse and complex use cases, performant enough to operate in real-time against high-speed network traffic, and straightforward to deploy in standard computing environments.This dissertation presents frameworks and algorithms that enable practical systems for traffic analysis on modern networks. We first describe Retina, a software framework that supports 100+ Gbps traffic analysis on a single commodity server. Retina strategically discards unneeded traffic and defers expensive processing operations to efficiently perform complex analysis tasks without specialized hardware. We highlight several case studies that demonstrate Retina's versatility and performance.Next, we describe CATO, an optimization framework for ML-based traffic analysis. With the widespread adoption of end-to-end encryption, many network traffic characteristics can only be inferred through statistical or machine learning-based techniques. However, existing ML-based solutions tend to overlook the practical challenges of running models against high-speed traffic. CATO combines multi-objective Bayesian optimization with direct end-to-end measurements to jointly optimize and validate the in-network performance of ML-based traffic analysis pipelines. We show how CATO can be implemented on top of Retina to construct ML-based traffic analysis applications that can be deployed in real-world networks on a single server.
- 일반주제명
- Decomposition
- 일반주제명
- Behavior
- 일반주제명
- Malware
- 일반주제명
- Streaming media
- 일반주제명
- Protocol
- 일반주제명
- Optimization techniques
- 일반주제명
- Retina
- 일반주제명
- Computer science
- 일반주제명
- Film studies
- 일반주제명
- Web studies
- 기타저자
- Stanford University.
- 기본자료저록
- Dissertations Abstracts International. 86-03A.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008250123s2024 us c eng d■001000017162953
■00520250211152116
■006m o d
■007cr#unu||||||||
■020 ▼a9798384338048
■035 ▼a(MiAaPQ)AAI31460308
■035 ▼a(MiAaPQ)Stanfordkw967bv6840
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a500
■1001 ▼aWan, Gerry.
■24510▼aPractical Systems For Traffic Analysis on Modern Networks
■260 ▼a[Sl]▼bStanford University▼c2024
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2024
■300 ▼a131 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 86-03, Section: A.
■500 ▼aAdvisor: Durumeric, Zakir.
■5021 ▼aThesis (Ph.D.)--Stanford University, 2024.
■520 ▼aNetwork traffic analysis is essential for understanding and securing production networks. It is routinely used by both operators and researchers to investigate network behaviors, identify security threats, and monitor performance. However, network traffic has grown increasingly opaque. The rise of end-to-end encryption and the rapid growth in network speeds have outpaced the capabilities of traditional analysis methods, hindering visibility into modern networks.Despite recent progress in the development of specialized tools for high-speed networks and machine learning (ML) techniques for analyzing encrypted traffic, such tools and techniques remain difficult to deploy in practice. Many systems built on advanced networking hardware are performant, but cannot accommodate complex analysis tasks involving reassembled or parsed network data. ML-based solutions can infer information from encrypted traffic but often do not meet the performance demands of running in real-world networks.Traffic analysis systems should be practical: versatile enough to enable diverse and complex use cases, performant enough to operate in real-time against high-speed network traffic, and straightforward to deploy in standard computing environments.This dissertation presents frameworks and algorithms that enable practical systems for traffic analysis on modern networks. We first describe Retina, a software framework that supports 100+ Gbps traffic analysis on a single commodity server. Retina strategically discards unneeded traffic and defers expensive processing operations to efficiently perform complex analysis tasks without specialized hardware. We highlight several case studies that demonstrate Retina's versatility and performance.Next, we describe CATO, an optimization framework for ML-based traffic analysis. With the widespread adoption of end-to-end encryption, many network traffic characteristics can only be inferred through statistical or machine learning-based techniques. However, existing ML-based solutions tend to overlook the practical challenges of running models against high-speed traffic. CATO combines multi-objective Bayesian optimization with direct end-to-end measurements to jointly optimize and validate the in-network performance of ML-based traffic analysis pipelines. We show how CATO can be implemented on top of Retina to construct ML-based traffic analysis applications that can be deployed in real-world networks on a single server.
■590 ▼aSchool code: 0212.
■650 4▼aDecomposition
■650 4▼aBehavior
■650 4▼aMalware
■650 4▼aStreaming media
■650 4▼aIntrusion detection systems
■650 4▼aProtocol
■650 4▼aOptimization techniques
■650 4▼aRetina
■650 4▼aComputer science
■650 4▼aFilm studies
■650 4▼aWeb studies
■690 ▼a0800
■690 ▼a0984
■690 ▼a0900
■690 ▼a0646
■71020▼aStanford University.
■7730 ▼tDissertations Abstracts International▼g86-03A.
■790 ▼a0212
■791 ▼aPh.D.
■792 ▼a2024
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17162953▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


