返回
A double-compression method for searchable network packets in network forensics and analysis
DOI:10.1016/j.compeleceng.2024.109535.png)
摘要
En 中文
Efficiently storing, searching, and extracting structured data such as network packets can significantly enhance cybersecurity analysis and artificial intelligence model training. This paper presents an efficient searchable double-compression method, PKTDC, which involves two processes: double compression and searchable decompression of specific packets. In double compression, PKTDC dynamically constructs an index to compress the searched data and then performs a second round of compression on this data and other payloads via a conventional algorithm. In searchable decompression, PKTDC reconstructs searchable packet information from the compressed data, partially decompresses the matched payloads, and stitches them together to restore the original packets. The experimental results show that PKTDC achieves up to 7.55% greater compression efficiency than LZMA2, reduces the search and decompression time by up to 21.6 times, reduces CPU usage by up to 5.51 times, and reduces memory usage by up to 2.9 times.
Keyword:
Compression
Decompression
Search
Packet
Storage
期刊
C
IF:
4.9
论文数:
6.7K
被引数:
1.3W
机构
引用论文
Characteristics of Individuals Who Developed Chorioamnionitis After Cerclage Placement During Pregnancy放置子宫颈环扎术后发生绒毛膜羊膜炎的个体特征
New Bit Pattern Based IPv6 Address Compression Techniques for 6LoWPAN Header Compression
IEEE ACCESS
IF3.6

