Skip to main content

2013 | OriginalPaper | Buchkapitel

15. Scalable and Robust Decentralized IP Traffic Flow Collection and Analysis (SCRIPT)

verfasst von : Burkhard Stiller, Cristian Morariu, Peter Racz

Erschienen in: Network-Embedded Management and Applications

Verlag: Springer New York

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

As the IP traffic observed on network operator’s backbones keeps increasing year by year, the analysis of NetFlow data metered for this traffic becomes a burden for centralized traffic monitoring solutions. Thus, SCRIPT proposes a decentralized accounting architecture and framework for NetFlow storage and analysis, which is flexible to allow for the development of distributed traffic analysis applications. SCRIPT mechanisms organize multiple PCs or AXP (Application Extension Platform) cards in an analysis network and route NetFlow records according to rules imposed by the analysis application. In turn, the evaluation of the prototype has shown that (a) this approach allows for a linear increase of the number of NetFlow records, which can be processed with the number of nodes in the SCRIPT deployment network, and (b) deploying SCRIPT on router-embedded AXP cards is improving an already existing infrastructure with the capability of storage and processing of NetFlow records.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Bailey MD, Cooke E, Jahanian F, Nazario J (2005) The Internet motion sensor: A distributed blackhole monitoring system. In: 12th annual network and distributed system security symposium (NDSS’05), San Diego, Feb 2005 Bailey MD, Cooke E, Jahanian F, Nazario J (2005) The Internet motion sensor: A distributed blackhole monitoring system. In: 12th annual network and distributed system security symposium (NDSS’05), San Diego, Feb 2005
2.
Zurück zum Zitat Brauckhoff D, Tellenbach B, Wagner A, May M, Lakhina A (2006) Impact of packet sampling on anomaly detection metrics. In: 6th ACM SIGCOMM Conference on Internet Measurements, Rio de Janeiro, Brazil, 17–25 Oct 2006 Brauckhoff D, Tellenbach B, Wagner A, May M, Lakhina A (2006) Impact of packet sampling on anomaly detection metrics. In: 6th ACM SIGCOMM Conference on Internet Measurements, Rio de Janeiro, Brazil, 17–25 Oct 2006
3.
Zurück zum Zitat Claise B (ed) (2004) Cisco systems NetFlow services export version 9; Internet engineering task force, Internet engineering task force RFC 3954, Oct 2004 Claise B (ed) (2004) Cisco systems NetFlow services export version 9; Internet engineering task force, Internet engineering task force RFC 3954, Oct 2004
4.
Zurück zum Zitat Claise B (ed) (2008) Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information; Internet Engineering Task Force RFC 5101, Jan 2008 Claise B (ed) (2008) Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of IP Traffic Flow Information; Internet Engineering Task Force RFC 5101, Jan 2008
5.
Zurück zum Zitat Duffield N, Lund C, Thorup M (2001) Charging from sampled network usage. In: 1st ACM SIGCOMM Workshop on Internet Measurements, San Francisco, Nov 2001 Duffield N, Lund C, Thorup M (2001) Charging from sampled network usage. In: 1st ACM SIGCOMM Workshop on Internet Measurements, San Francisco, Nov 2001
6.
Zurück zum Zitat FIPS 180-2 (2002) Secure Hash Standard (SHS), National Institute of Standards and Technology, Aug 2002, amended Feb 2004 FIPS 180-2 (2002) Secure Hash Standard (SHS), National Institute of Standards and Technology, Aug 2002, amended Feb 2004
7.
Zurück zum Zitat Han SH, Kim MS, Ju HT, Hong JWK (2002) The architecture of NG-MON: a passive network monitoring system for high-speed IP networks. In 13th IFIP/IEEE International Workshop on Distributed Systems: Operations and Management (DSOM’02), Montreal, Canada, Oct 2002 Han SH, Kim MS, Ju HT, Hong JWK (2002) The architecture of NG-MON: a passive network monitoring system for high-speed IP networks. In 13th IFIP/IEEE International Workshop on Distributed Systems: Operations and Management (DSOM’02), Montreal, Canada, Oct 2002
8.
Zurück zum Zitat Henke C, Schmoll C, Zseby T (2008) Empirical evaluation of hash functions for multipoint measurements. ACM Computer Communication Review 38(3): 39–50 Henke C, Schmoll C, Zseby T (2008) Empirical evaluation of hash functions for multipoint measurements. ACM Computer Communication Review 38(3): 39–50
9.
Zurück zum Zitat Jimenez R, Osmani F, Knutsson B (2011) Sub-second lookups on a large-scale Kademlia based overlay. In: 11th IEEE International Conference on Peer-to-Peer Computing 2011, Kyoto, Japan, Aug 2011 Jimenez R, Osmani F, Knutsson B (2011) Sub-second lookups on a large-scale Kademlia based overlay. In: 11th IEEE International Conference on Peer-to-Peer Computing 2011, Kyoto, Japan, Aug 2011
10.
Zurück zum Zitat Kitatsuji Y, Yamazaki K (2004) A distributed real-time tool for IP-flow measurement. In: international symposium on applications and the Internet, Tokyo, Japan, Jan 2004 Kitatsuji Y, Yamazaki K (2004) A distributed real-time tool for IP-flow measurement. In: international symposium on applications and the Internet, Tokyo, Japan, Jan 2004
11.
Zurück zum Zitat Maymounkov P, Mazières D (2002) Kademlia: a Peer-to-Peer information system based on the XOR metric. IPTPS, Cambridge Maymounkov P, Mazières D (2002) Kademlia: a Peer-to-Peer information system based on the XOR metric. IPTPS, Cambridge
12.
Zurück zum Zitat Mao Y, Chen K, Wang D, Zheng W (2001) Cluster-based online monitoring system of web traffic. In: 3rd International Workshop on Web Information and Data Management, Atlanta, Georgia, USA, Nov 2001 Mao Y, Chen K, Wang D, Zheng W (2001) Cluster-based online monitoring system of web traffic. In: 3rd International Workshop on Web Information and Data Management, Atlanta, Georgia, USA, Nov 2001
13.
Zurück zum Zitat Morariu C, Racz P, Stiller B (2009) Design and implementation of a distributed platform for sharing IP flow records. In: 20th IFIP/IEEE International Workshop on Distributed Systems: Operations and Management (DSOM’09), Venice, Italy, Oct 2009 Morariu C, Racz P, Stiller B (2009) Design and implementation of a distributed platform for sharing IP flow records. In: 20th IFIP/IEEE International Workshop on Distributed Systems: Operations and Management (DSOM’09), Venice, Italy, Oct 2009
14.
Zurück zum Zitat Morariu C, Kramis T, Stiller B (2008) DIPStorage: distributed storage of IP flow records. In: 16th IEEE workshop on local and metropolitan area networks, Cluj-Napoca Romania, Sept 2008 Morariu C, Kramis T, Stiller B (2008) DIPStorage: distributed storage of IP flow records. In: 16th IEEE workshop on local and metropolitan area networks, Cluj-Napoca Romania, Sept 2008
15.
Zurück zum Zitat Morariu C, Racz P, Stiller B (2010) SCRIPT: a framework for scalable real-time IP flow record analysis. In: 12th IEEE/IFIP Network Operations and Management Symposium (NOMS 2010), IEEE, Osaka, Japan, April 2010 Morariu C, Racz P, Stiller B (2010) SCRIPT: a framework for scalable real-time IP flow record analysis. In: 12th IEEE/IFIP Network Operations and Management Symposium (NOMS 2010), IEEE, Osaka, Japan, April 2010
16.
Zurück zum Zitat Postel J (1980) User datagram protocol. Internet Engineering Task Force, RFC 768, August 1980 Postel J (1980) User datagram protocol. Internet Engineering Task Force, RFC 768, August 1980
17.
Zurück zum Zitat Rivest R (1992) The MD5 message-digest algorithm. Internet Engineering Task Force RFC 1321, April 1992 Rivest R (1992) The MD5 message-digest algorithm. Internet Engineering Task Force RFC 1321, April 1992
18.
Zurück zum Zitat Schulzrinne H, Casner S, Frederick R, Jacobson V (2003) RTP: a transport protocol for real-time applications. Internet Engineering Task Force RFC 3550, July 2003 Schulzrinne H, Casner S, Frederick R, Jacobson V (2003) RTP: a transport protocol for real-time applications. Internet Engineering Task Force RFC 3550, July 2003
19.
Zurück zum Zitat Stewart R, Xie Q, Morneault K, Sharp C, Schwarzbauer H, Taylor T, Rytina I, Kalla M, Zhang L, Paxson V (2000) Stream control transmission protocol. Internet Engineering Task Force RFC 2960, Oct 2000 Stewart R, Xie Q, Morneault K, Sharp C, Schwarzbauer H, Taylor T, Rytina I, Kalla M, Zhang L, Paxson V (2000) Stream control transmission protocol. Internet Engineering Task Force RFC 2960, Oct 2000
Metadaten
Titel
Scalable and Robust Decentralized IP Traffic Flow Collection and Analysis (SCRIPT)
verfasst von
Burkhard Stiller
Cristian Morariu
Peter Racz
Copyright-Jahr
2013
Verlag
Springer New York
DOI
https://doi.org/10.1007/978-1-4419-6769-5_15

Neuer Inhalt