Traffic repositories with TCP/IP header information are very important for network analysis. Researchers often assume that such repositories reliably represent all traffic that has been flowing over the network; little thoughts are made regarding the consistency of these repositories. Still, for various reasons, the traffic capturing process may have missed packets. For certain kinds of analysis, for example loss measurements, such inconsistencies may lead to the wrong conclusions. This paper proposes an algorithm to detect such inconsistencies, using the idea of "fake gaps". A prototype has been developed, and used to test two well-known repositories: the WIDE and Simpleweb repositories. The paper shows that both repositories contain several inconsistencies. © 2009 Springer Berlin Heidelberg.
CITATION STYLE
Lastdrager, E., & Pras, A. (2009). Consistency analysis of network traffic repositories. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 5733 LNCS, pp. 217–226). https://doi.org/10.1007/978-3-642-03700-9_23
Mendeley helps you to discover research relevant for your work.