16.11.2014 Views

Visualizza - Garr

Visualizza - Garr

Visualizza - Garr

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Scripting+nfdump<br />

•Nfdump prevede un output<br />

machine readable tramite<br />

l’opzione: -o pipe<br />

•Il formato di output è riportato<br />

nella tabella, ogni campo è<br />

separato da un ”pipe”(|).<br />

•Gli indirizzi IP sono<br />

rappresentati da numeri interi.<br />

•L’uso di filtri e<br />

dell’aggregazione non modifica<br />

il formato di output, ma solo il<br />

riempimento dei campi.<br />

Address family<br />

Time first seen<br />

msec first seen<br />

Time last seen<br />

msec last seen<br />

Protocol<br />

Src address<br />

Src port<br />

Dst address<br />

Dst port<br />

Src AS<br />

Dst AS<br />

Input IF<br />

Output IF<br />

TCP Flags<br />

Tos<br />

Packets<br />

Bytes<br />

PF_INET or PF_INET6<br />

UNIX time seconds<br />

Mili seconds first seen<br />

UNIX time seconds<br />

Mili seconds first seen<br />

Protocol<br />

Src address as 4 consecutive 32bit<br />

numbers<br />

Src port<br />

Dst address as 4 consecutive 32bit<br />

numbers.<br />

Dst port<br />

Src AS number<br />

Dst AS number<br />

Input Interface<br />

Output Interface<br />

000001 FIN.<br />

000010 SYN<br />

000100 RESET<br />

001000 PUSH<br />

010000 ACK<br />

100000 URGENT<br />

Type of Service<br />

Packets<br />

Bytes<br />

Nino Ciurleo, Alessandro Inzerilli, Simona Venuti<br />

GARR WS9, Roma, 15.06.2009<br />

96

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!