Holger Dreger's Publications

Packet Trace Manipulation Framework for Test Labs
Citation key RDFS-PTMFTL-04
Author Rupp, Andy and Dreger, Holger and Feldmann, Anja and Sommer, Robin
Title of Book IMC '04: Proceedings of the 4th ACM SIGCOMM conference on Internet measurement
Pages 251–256
Year 2004
ISBN 1-58113-821-0
DOI http://dx.doi.org/10.1145/1028788.1028821
Location Taormina, Sicily, Italy
Address New York, NY, USA
Publisher ACM Press
Abstract Evaluating network components such as network intrusion detection systems, firewalls, routers, or switches suffers from the lack of available network traffic traces that on the one hand are appropriate for a specific test environment but on the other hand have the same characteristics as actual traffic. Instead of just capturing traffic and replaying the trace, we identify a set of packet trace manipulation operations that enable us to generate a trace bottom-up:o ur trace primitives can be traces from different environments or artificially generated ones; our basic operations include merging of two traces, moving a flow across time, duplicating a flow, and stretching a flow's time-scale. After discussing the potential as well as the dangers of each operation with respect to analysis at different protocol layers, we present a framework within which these operations can be realized and show an example configuration for our prototype.
