Title :
Flexible Flow Aggregation for Adaptive Network Monitoring
Author :
Dressler, Falko ; Munz, Gerhard
Author_Institution :
Dept. of Comput. Sci. 7, Erlangen Univ.
Abstract :
Network monitoring is a major building block for many domains in communication networks. Besides typical accounting mechanisms and the emerging area of charging in next generation networks, especially network security solutions rely on efficient and optimized monitoring. Network monitoring in high-speed networks is usually based on flow accounting and aggregation techniques represent a necessary enhancement in order to cope with increasing amounts of monitoring data that accrue with the ever-growing network capacities. In this paper, we propose a flexible flow aggregation mechanism that can be directly employed on a monitoring probe to reduce the memory and processing demands. Alternatively, it can work as a concentrator that collects flow data from multiple monitoring probes, combines and aggregates them and forwards the results to an analyzer. We verified and evaluated the aggregation mechanism by integrating it into our monitoring probe Vermont. Our approach opens new prospects for high-speed network monitoring and allows coping with special situations that cannot be treated satisfyingly by traditional flow accounting, such as distributed denial-of-service attacks causing very high numbers of flows. Aggregated flow data are an easy-to-handle form of packet information especially for anomaly detection and accounting issues
Keywords :
computer network management; telecommunication congestion control; telecommunication security; adaptive network monitoring probe; aggregated flow data; communication network security; flexible flow aggregation mechanism; flow accounting; multiple monitoring probe; packet information; processing demand; Adaptive systems; Computer crime; Computer networks; Computer science; Computerized monitoring; IP networks; Next generation networking; Probes; Protocols; Sampling methods;
Conference_Titel :
Local Computer Networks, Proceedings 2006 31st IEEE Conference on
Conference_Location :
Tampa, FL
Print_ISBN :
1-4244-0418-5
Electronic_ISBN :
0742-1303
DOI :
10.1109/LCN.2006.322180