Processing and Extending Flow-Based Network Traffic Measurements

Sven Anderson · 2009

With the increasing usage of the Internet and IP networks for critical applications, network monitoring becomes more important. Flow-profiling is currently the most common measurement technology used for IP network monitoring. This dissertation addresses several challenges of flow-based network traffic measurements. The first part describes Mouse Trapping, a method to reduce the measured flow data with a limited information loss, in order to cope with the typically large amounts of data. The second part presents the interactive flow data analysis tool FloX, which helps to identify the reasons for sudden traffic peaks in large amounts of flow records. The third part introduces SIPFIX, a scheme for distributed monitoring of Voice-over-IP and media traffic, which includes the processing of application layer information into the general distributed IP flow processing by extending the standard for IP flow information export (IPFIX).

Read the paper · More papers on PaperTik