12.07.2015 Views

Davide Cherubini - PhD Thesis - UniCA Eprints

Davide Cherubini - PhD Thesis - UniCA Eprints

Davide Cherubini - PhD Thesis - UniCA Eprints

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5.2 Traffic monitoring• Sets - are grouping of traffic patterns to be observed. They can be definedover multiple directions.JKFlow may appear as a complete FlowScan module but it has some drawback.For example, the subnets are defined by mean of a list of IP addressesand, in order to define a “direction” between two routers a high number of IPaddresses are needed.In other words, JKFlow isn’t able to perform an AS-to-AS report 1 . This isa fundamental capability of the monitoring tool needed for the present work,mainly because the Italian backbone is organized per AS. To solve this problemwe decided to develop a new module, directly form JKFlow, called ICEFlow.5.2.2.5 ICEFlowICEFlow is a network traffic flow visualization, analysis, and reporting tool basedon open source tools, namely RRD-Tools, Flow-tools and JKFlow, and has beendeveloped by myself and C. Murgia.ICEFlow is able to collect, send, process, and generate reports from NetFlowformat (indigenous to Cisco routers) and to identify and distinguish the trafficper single protocol (ICMP, TCP, UDP, ) and per single service/application (peerto-peerapplications, FTP, HTTP, e-mail, ). Furthermore, its main characteristicsare:• Granularity - it can collect and analyze traffic flowing (in both the directions)in a single interface of a router, or the flows incoming/outgoingto/from a group of routers, as well as in a subnet or in an AutonomousSystem.• Robustness - it can easily tackle network configuration changes and theinsertion of new protocols and applicationsThe results are displayed in a graphical fashion or accessing downloadabletextual files, with variable time-basis (by default from 1 day to 1 year) anddifferent scale of traffic (Mbps, packets, flows).1 In the last version of JKFlow the capability of monitoring AS-to-AS traffic has been implemented.This add-on has been done after that the phase of collecting traffic for the presentwork was finished.35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!