POSTER: DeePCAP: Enabling High-Fidelity and Cost-Efficient Archival Packet Trace Storage
Abstract
Long-term network packet traces (e.g., pcaps), if available, can enable and inform lots of management tasks. However, storing packet data at scale is very expensive, forcing operators to choose between coarse historical summaries or short retention windows. In this context, deep generative compression (DGC) offers a new hope to store compact model parameters and regenerate structurally accurate traces on demand. We evaluate the suitability of recent deep generative approaches [21, 24] for packet trace modeling and generation. We find that their fidelity metrics are disconnected from the domain-specific queries/use cases, and they have bad cost-fidelity trade-off. We propose DeePCAP, an end-to-end trace storage system to close this gap. DeePCAP introduces a query-driven fidelity framework spanning packet- and flow-level queries to tackle the fidelity disconnection, and proposes a novel dimensionality reduction approach using frequency domain encoding to improve cost-fidelity trade-off. Our preliminary results show that DeePCAP achieves the best fidelity on the 100+ query suite and the strongest cost-fidelity trade-off.