Smart Collection and Storage Method for Network Traffic Data
• Technical Report
Publisher
Software Engineering Institute
CMU/SEI Report Number
CMU/SEI-2014-TR-011DOI (Digital Object Identifier)
10.1184/R1/6583826.v1Topic or Tag
Abstract
Captured network data enables an organization to perform routine tasks such as network situational awareness and incident response to security alerts. The process of capturing, storing, and evaluating network traffic as part of monitoring is an increasingly complex and critical problem. With high-speed networks and ever-increasing network traffic volumes, full-packet traffic capture solutions can require petabytes of storage for a single day. The capacity needed to store full-packet captures for a time frame that permits the needed analysis is unattainable for many organizations. A tiered network storage solution, which stores only the most critical or effective types of traffic in full-packet captures and the rest as summary data, can help organizations mitigate the storage issues while providing the detailed information they need. This report discusses considerations and decisions to be made when designing a tiered network data storage solution. It includes a method, based on a cost-effectiveness model, that can help organizations decide what types of network traffic to store at each storage tier. The report also uses real-world network measurements to show how storage requirements change based on what traffic is stored in which storage tier.
Part of a Collection
Network Situational Awareness: Best Practices
Cite This Technical Report
Horneman, A., & Dell, N. (2014, September 15). Smart Collection and Storage Method for Network Traffic Data. (Technical Report CMU/SEI-2014-TR-011). Retrieved December 21, 2024, from https://doi.org/10.1184/R1/6583826.v1.
@techreport{horneman_2014,
author={Horneman, Angela and Dell, Nathan},
title={Smart Collection and Storage Method for Network Traffic Data},
month={{Sep},
year={{2014},
number={{CMU/SEI-2014-TR-011},
howpublished={Carnegie Mellon University, Software Engineering Institute's Digital Library},
url={https://doi.org/10.1184/R1/6583826.v1},
note={Accessed: 2024-Dec-21}
}
Horneman, Angela, and Nathan Dell. "Smart Collection and Storage Method for Network Traffic Data." (CMU/SEI-2014-TR-011). Carnegie Mellon University, Software Engineering Institute's Digital Library. Software Engineering Institute, September 15, 2014. https://doi.org/10.1184/R1/6583826.v1.
A. Horneman, and N. Dell, "Smart Collection and Storage Method for Network Traffic Data," Carnegie Mellon University, Software Engineering Institute's Digital Library. Software Engineering Institute, Technical Report CMU/SEI-2014-TR-011, 15-Sep-2014 [Online]. Available: https://doi.org/10.1184/R1/6583826.v1. [Accessed: 21-Dec-2024].
Horneman, Angela, and Nathan Dell. "Smart Collection and Storage Method for Network Traffic Data." (Technical Report CMU/SEI-2014-TR-011). Carnegie Mellon University, Software Engineering Institute's Digital Library, Software Engineering Institute, 15 Sep. 2014. https://doi.org/10.1184/R1/6583826.v1. Accessed 21 Dec. 2024.
Horneman, Angela; & Dell, Nathan. Smart Collection and Storage Method for Network Traffic Data. CMU/SEI-2014-TR-011. Software Engineering Institute. 2014. https://doi.org/10.1184/R1/6583826.v1