03.09.2013 Views

Implementation of data collection tools using NetFlow for statistical ...

Implementation of data collection tools using NetFlow for statistical ...

Implementation of data collection tools using NetFlow for statistical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

2 Theoretical background<br />

Illustration 3: <strong>NetFlow</strong> overview<br />

It is worth mentioning that a TCP header is only 20 bytes in size [51].<br />

See appendix 8.2 <strong>for</strong> in<strong>for</strong>mation on how to configure <strong>NetFlow</strong> on Cisco devices.<br />

2.5 sFlow<br />

Much like <strong>NetFlow</strong>, sFlow collects network traffic in<strong>for</strong>mation <strong>for</strong> use in monitoring the network. It<br />

is an industry standard, which means it is supported on a majority <strong>of</strong> devices. It too sends network<br />

traffic in<strong>for</strong>mation to a collector <strong>for</strong> further analysis. This collector is a computer running any <strong>of</strong> the<br />

many available programs <strong>for</strong> gathering flow-<strong>data</strong>. It works by sampling the network traffic – that is,<br />

it tags packets, one out <strong>of</strong> every N packets, and send it to the collector. The marked packet's header<br />

in<strong>for</strong>mation is saved into a new packet and sent to the collector once it reaches 1500 bytes (the<br />

maximum size <strong>for</strong> a packet). Along with the header in<strong>for</strong>mation from packets, in<strong>for</strong>mation about the<br />

sampling rates and interface id are also included. This type <strong>of</strong> sampling is called random sampling.<br />

The other type <strong>of</strong> sampling method involves basing the samples on a time-based polling interval<br />

and is called counter sampling. [39] [40] [41] [42] [43][46]<br />

2.6 IPFIX<br />

Internet Protocol Flow In<strong>for</strong>mation Export (IPFIX) is a protocol created by the IETF in an attempt<br />

to create a common universal standard <strong>for</strong> flow in<strong>for</strong>mation from routers and other devices,<br />

eliminating the need <strong>for</strong> a specific vendor to create a version <strong>of</strong> its own [44]. Being based on Cisco's<br />

<strong>NetFlow</strong> version 9, the characteristics <strong>for</strong> defining a flow are the same - same source, same<br />

19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!