Труды Института системного программирования РАН (Oct 2018)

Model of data handling for in-depth analysis of network traffic

  • A. I. Get'man,
  • V. P. Ivannikov,
  • Yu. V. Markin,
  • V. A. Padaryan,
  • A. Yu. Tikhonov

DOI
https://doi.org/10.15514/ISPRAS-2015-27(4)-1
Journal volume & issue
Vol. 27, no. 4
pp. 5 – 22

Abstract

Read online

The article suggests a new object model of data for in-depth analysis of network traffic. In contrast to the model used by most existing network analyzers, such as Wireshark or Snort, the core of our model supports data streams reassembling and next processing. The model also provides a convenient universal mechanism for binding parsers. So one can develop parsers independently at all. Our model also provides processing of modified, e.g. compressed or encrypted, data. It forms the basis of the infrastructure for in-depth analysis of network traffic.

Keywords