12.07.2015 Views

Davide Cherubini - PhD Thesis - UniCA Eprints

Davide Cherubini - PhD Thesis - UniCA Eprints

Davide Cherubini - PhD Thesis - UniCA Eprints

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

5.2 Traffic monitoringcollector, the analyzer, and the Web Server are condensed in a single hardwaredevice.Figure 5.3: NetFlow collector architecture5.2.2.1 CFlowdCAIDA’s CFlowd is a flow analysis tool released to enable ISPs to collect datafrom NetFlow routers. This analysis package is composed by three programs:cflowdmux, cflowd, and cfdcollect.cflowdmux accepts Cisco flow-export packets arriving from the NetFlow routersas UDP packets and saves them in shared memory buffers.Directly from these buffers, cflowd creates tabular data to be inputted to cfdcollect,which will store these data in different files.Currently, CFlowd is no longer supported by the CAIDA team, and this isthe reason that pushed this work to consider a different tool, that is Flow-Tools.5.2.2.2 Flow-ToolsFlow-Tools is a set of programs for processing and generating reports from Net-Flow data. The tools can run in a single server as well as in multiple servers forlarge collecting networks and it is compatible with several versions of NetFlow.NetFlow data is collected, by default, every 30 seconds and stored in portablefiles every 5 minutes. These files may be analyzed by the following programs that31

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!