Abstract: Archiving raw network traffic is fundamental for network forensics and troubleshooting. In order to efficiently retrieve specific entries from large-scale archives, multi-attribute queries ...