Davide Cherubini - PhD Thesis - UniCA Eprints
Davide Cherubini - PhD Thesis - UniCA Eprints
Davide Cherubini - PhD Thesis - UniCA Eprints
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
5.2 Traffic monitoring1. the IP source address;2. the IP destination address;3. the Source port ;4. the Destination port ;5. the Layer 3 protocol type ;6. the Class of Service;7. the Router interface.All packets with the same characteristics are assembled into a single flowand then packets and bytes tallied. The Cisco’s NetFlow is a part of the CiscoInternetwork Operating System (IOS) and enables routers to condense all theseinformation in a cache memory called the NetFlow cache as shown in Figure 5.1 1 .It is possible to set the sampling rate of the packets in order to avoid the loss ofperformance of the router.Figure 5.1: Exporting IP attributes to NetFlow cacheTwo primary methods to access and analyze NetFlow data exist, which are theCommand Line Interface (CLI) with its “show” commands, as shown in Figure5.2, or utilizing a reporting tool running in a server.1 Courtesy of Cisco Systems29