A Heuristic-Based Approach to Real-Time TCP State and Retransmission Analysis
James E. Swaro · OhioLink ETD Center (Ohio Library and Information Network) · 2015
This study focuses on understanding how to classify out-of-order network traffic sent using the Transport Control Protocol(TCP).Packets that arrive out of order are the result of network reordering or loss recovery.TCP initiates loss recovery in response to the perceived loss of data, decreasing the congestion window and throughput of the connection.When TCP reacts poorly to loss, throughput may drop, latency may increase, and congestion collapse may occur.This thesis analyzes TCP traffic from an arbitrary observation point in a network, rather than at the TCP endpoint.Observing traffic at a TCP endpoint inhibits the inference of loss and detection of network reordering in one direction of the connection.Alternatively, observing traffic at an arbitrary point between two TCP endpoints allows inference of loss and detection of network reordering in both directions.Positioning the observation point at an arbitrary point can increase the diversity of observed connections, increasing the likelihood of detecting rare forms of aberrant behavior.In this paper, several algorithms and heuristics for classification of out-of-order TCP traffic are analyzed and implemented in a new TCP traffic analyzer called tcprs.An in-depth analysis of each algorithm and heuristic is given and compared with the results from tcptrace and tcpcsm.It was found that tcprs achieves an improvement in classification accuracy as compared with tcptrace and tcpcsm.I would like to thank my advisor, Dr. Ostermann, for the constant stream of ideas and suggestions.I am thankful for my opportunity to work with him and the rest of the students in the IRG Lab.A special thanks to Dr. Kruse for his thoughts on my ideas about traffic analysis.Thanks to