Traffic Monitoring Activities in CNU - PowerPoint PPT Presentation

1 / 10
About This Presentation
Title:

Traffic Monitoring Activities in CNU

Description:

Traffic Monitoring Research in Data Networks Lab, CNU ... Measurement of CDMA 1x EV-DO TCP ... IPv6 covert channels. Evolution of anomaly traffic in IPv4 ? ... – PowerPoint PPT presentation

Number of Views:48
Avg rating:3.0/5.0
Slides: 11
Provided by: seongh
Category:

less

Transcript and Presenter's Notes

Title: Traffic Monitoring Activities in CNU


1
Traffic Monitoring Activities in CNU
  • Youngseok Lee
  • Chungnam National University
  • lee_at_cnu.ac.kr
  • http//networks.cnu.ac.kr
  • 2006.10.28

2
Traffic Monitoring Research in Data Networks Lab,
CNU
  • Collecting NetFlow v5 flows in campus networks
  • 2004 , non-sampled
  • Measurement of CDMA 1x EV-DO TCP performance
  • 2005
  • Development of IPFIX-based traffic monitoring
    applications
  • Signature-based traffic monitoring
  • Mobile IPv6 traffic monitoring
  • IPv6 anomaly traffic monitoring
  • RTP application performance monitoring

3
A Signature-aware Traffic Monitoring Method
IPFIX header
IPFIX message
IPFIX flow data set
IPFIX template set
4
A Signature-aware Traffic Monitoring Method
(contd)
the signature ID 2586 is the eDonkey traffic .
  • Flow collector WinIPFIX

Lists of signatures to classify traffic at graphs
Top 10 lists of signatures according to amount of
traffic
5
MIPv6 Traffic Monitoring
IPv6 Network
CN
IPFIX Flow Collector
IPv6 Router
  • Flow before handover

IPFIX flow data
MIPv6 Access Router with IPFIX
HA
2. BU/BA
3. Tunneled IPv6 flow
AP
MN
MN
6
IPv6 Anomaly Traffic Monitoring
  • IPv6 anomaly traffic ?
  • IPv6 tunneling was already used for avoiding
    detection of attacks in IPv4
  • Several IPv6 attacking tools
  • IPv6 covert channels
  • Evolution of anomaly traffic in IPv4 ?
  • Examples of new templates for monitoring IPv6
    anomaly traffic
  • ICMPv6 NS/NA template
  • ICMPv6 RA template
  • Basic template extension header flag
  • IPv6-over-IPv4 tunnel information

7
RTP-based Application Performance Monitoring
  • RTP applications
  • DVTS, MPEG2-TS
  • QoS metrics
  • Throughput, delay, jitter, loss
  • IPFIX extension
  • IPFIX templates that can monitor RTP header fields

8
RTP-based Traffic Monitoring
  • Java program for RTP monitoring

9
Summary
  • Collaboration
  • Topics
  • IPv6 traffic measurement analysis with QGPOP and
    KOREN
  • MIPv6 traffic measurement
  • Flow analysis with QGPOP, KU, and CNU
  • Goals
  • Writing good papers
  • Friendship
  • Proposal
  • Regular workshop for graduate students

10
Q A
Write a Comment
User Comments (0)
About PowerShow.com