• español
    • English
  • Login
  • English 
    • español
    • English
  • Publication Types
    • bookbook partconference objectdoctoral thesisjournal articlemagazinemaster thesispatenttechnical documentationtechnical report
View Item 
  •   IMDEA Networks Home
  • View Item
  •   IMDEA Networks Home
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.

Columnar Packet Traces for Scalable Encrypted-Internet Measurement

Share
Files
pcaptoparquet.pdf (361.2Kb)
Identifiers
URI: https://hdl.handle.net/20.500.12761/2103
Metadata
Show full item record
Author(s)
Rojo, Pablo; Ramirez Rondon, Juan Marcos; Mancuso, Vincenzo; Fernández Anta, Antonio
Date
2026-06
Abstract
Internet traffic volumes continue to grow while transport and application encryption increasingly limit payload visibility. However, modern transport protocols such as QUIC complicate traditional packet-trace analytics built around pcap (e.g., tshark-to-CSV), and row-oriented extraction increases the cost of repeated analysis. This paper makes repeated offline mea- surement practical by converting packet traces into a column- oriented representation that separates one-time parsing from downstream analytics. Concretely, we introduce an advanced benchmarked software implementation that converts pcap files to the column-oriented Apache parquet format. To the best of our knowledge, this is among the first end-to-end pipelines that (i) converts pcap/pcapng traces into parquet with a schema aimed at repeated offline measurement and (ii) is engineered around a convert-once, query-many workflow with measured end-to-end time-to-insight benefits. The pipeline leverages par- allel parsing to produce a columnar dataset that can be queried efficiently by standard analytics engines. We benchmark end- to-end time-to-insight and storage costs across representative workloads and diverse datasets. Our results show that after a one-time conversion, subsequent analyses can exploit column pruning and vectorized scans to reduce query time compared with re-parsing pcap or re-extracting row-oriented text formats, while maintaining storage costs competitive with compressed pcap and CSV baselines.
Share
Files
pcaptoparquet.pdf (361.2Kb)
Identifiers
URI: https://hdl.handle.net/20.500.12761/2103
Metadata
Show full item record

Browse

All of IMDEA NetworksBy Issue DateAuthorsTitlesKeywordsTypes of content

My Account

Login

Statistics

View Usage Statistics

Dissemination

emailContact person Directory wifi Eduroam rss_feed News
IMDEA initiative About IMDEA Networks Organizational structure Annual reports Transparency
Follow us in:
Community of Madrid

EUROPEAN UNION

European Social Fund

EUROPEAN UNION

European Regional Development Fund

EUROPEAN UNION

European Structural and Investment Fund

© 2021 IMDEA Networks. | Accesibility declaration | Privacy Policy | Disclaimer | Cookie policy - We value your privacy: this site uses no cookies!