DocumentCode
2562954
Title
A distributed real-time tool for IP-flow measurement
Author
Kitatsuji, Yoshinori ; Yamazaki, Katsuyuki
Author_Institution
KDDI R&D Labs. Inc., Saitama, Japan
fYear
2004
fDate
2004
Firstpage
91
Lastpage
98
Abstract
It is getting more difficult to monitor multiple services as well as to detect and/or to trace denial of service attacks with only tools showing graphs of the whole IP layer traffic like MRTG or by checking counters of router interfaces. In this paper, we discuss the specification of a software-based real-time measurement tool for flow which consists of multiple capture devices, a manager device and user interface devices, enabling flexible flow definition on demand without stopping system and working with IPv4 and/or IPv6, while also enabling high performance. With this discussion, we propose its architecture, bit-pattern-based flow definition method and data structure. Then we report on the performance evaluation of a prototype of proposed real-time flow measurement tools developed on PC-UNIXs and show that the number of bit-pattern composing flow definitions impact on the performance. Lastly we show an example of measuring flows in a real world environment and confirm that the flow extraction is simplified.
Keywords
IP networks; distributed processing; graphical user interfaces; performance evaluation; real-time systems; routing protocols; telecommunication network management; telecommunication traffic; transport protocols; Daniel-of-Service attacks; IP layer traffic; IP-flow measurement; IPv4; IPv6; PC-UNIX; bit-pattern-based flow definition; data structure; distributed real-time tool; flexible flow definition; flow extraction; manager device; multi router traffic grapher; multiple capture devices; performance evaluation; real-time flow measurement; router interfaces; user interface; Computer crime; Counting circuits; Data mining; Data structures; Data visualization; Fluid flow measurement; Monitoring; Prototypes; Telecommunication traffic; User interfaces;
fLanguage
English
Publisher
ieee
Conference_Titel
Applications and the Internet, 2004. Proceedings. 2004 International Symposium on
Print_ISBN
0-7695-2068-5
Type
conf
DOI
10.1109/SAINT.2004.1266103
Filename
1266103
Link To Document