Traffic Analysis on High-Speed Internet Links

نویسنده

  • Lothar Braun
چکیده

The past years have seen an increase in the importance of computer networks for many tasks in day-to-day life. Network services are crucial for many business work-flows and become more important for the private life driven by new services such as social networks or online video streaming portals. As the need for network service availability increases, operators see a growing need for understanding the current state of their networks. Monitoring techniques for detecting network failures, attacks on end systems, or potential bottlenecks that could be mitigated by careful network optimization receive more attention in the research and business community. Many current traffic analysis systems employ deep packet inspection (DPI) in order to analyze network traffic. These systems include intrusion detection systems, software for network traffic accounting, traffic classification, or systems for monitoring service-level agreements. Traffic volumes and link speeds of current enterprise and ISP networks, however, transform the process of inspecting traffic payload into a challenging task. A traffic analysis setup needs to be properly configured in order to meet the challenges posed by traffic volumes in current high-speed networks. This dissertation evaluates the performance of current packet capturing solutions of standard operating systems on commodity hardware. We identify and explain bottlenecks and pitfalls within the capturing stacks, and provide guidelines for users on how to configure their capturing systems for optimal performance. Furthermore, we propose improvements to the operating system’s capturing processes that reduce packet loss, and evaluate their impact on capturing performance. Depending on the computational complexity of the desired traffic analysis application, even the best-tuned capturing setups can suffer packet loss if the employed hardware is short in available computational resources. We address this problem by presenting and evaluating new sampling algorithms that can be deployed in front of a traffic analysis application to reduce the amount of inspected packets without degrading the results of the analysis significantly. These algorithms can be used in conjunction with multicore-aware network traffic analysis setups for exploiting the capabilities of multi-core hardware. The presented analysis architecture is demonstrated to be suitable for live traffic measurements for security monitoring, for the analysis of security protocols and for traffic analysis for network optimization.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Experiences from passive Internet Traffic Measurements

Due to its versatility, flexibility and fast development, the modern Internet is far from being well understood in its entirety. A good way to learn more about how the Internet functions is to collect and analyze real Internet traffic. This paper addresses several major challenges of Internet traffic monitoring, which is a prerequisite for performing traffic analysis. The challenges discussed w...

متن کامل

Passive internet measurement: Overview and guidelines based on experiences

Due to its versatility, flexibility and fast development, the modern Internet is far from being well understood in its entirety. A good way to learn more about how the Internet functions is to collect and analyze real Internet traffic. This paper addresses several major challenges of Internet traffic monitoring, which is a prerequisite for performing traffic analysis. The issues discussed will ...

متن کامل

Internet Application Traffic Monitoring and Analysis 인터넷 응용 트래픽 수집 및 분석 Internet Application Traffic Monitoring and Analysis Internet Application Traffic Monitoring and Analysis

Two critical problems exist in traffic monitoring and analysis of today's Internet traffic compared to the past network environment. The first is how to capture and handle the huge amount of traffic data in a real-time manner generated from high-speed network links, such as 2.5 Gbps and higher. The second is how to analyze diverse and complex types of traffic generated by many different types o...

متن کامل

IP Over Direct Links: IP Over Sonet

The explosive growth in Internet traffic has created the need to transport IP on high-speed links. In the days of low traffic volume between IP routers, bandwidth partitions over a common interface made it attractive to carry IP over a frame relay and/or an ATM backbone. As the traffic grows, it is becoming more desirable to carry IP traffic directly over the synchronous optical network (SONET)...

متن کامل

Packet Loss Analysis of Load-Balancing Switch with ON/OFF Input Processes

Lately, the number of Internet users and, correspondingly, the amount of traversing traffic is growing extremely fast. In spite of the fact that transmission links – mostly optical fibers – have high capacity, the internet routers still remain a point of traffic bottleneck. The construction of highly scalable switches for high-speed transmission still remains a real challenge for designers. In ...

متن کامل

Analysis of Network Traffic and its Application to Design of High–Speed Routers

A rapid growth of the Internet and proliferation of new multimedia applications lead to demands of high speed and broadband network technologies. Routers are also necessary to follow up the growth of link bandwidths. From this reason, there have been many researches on high speed routers having switching capabilities. To have an expected effect, however, a control parameters set based on traffi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014