Title: Measurement, Analysis, Visualization of Internet Topology, Workload, Performance and Routing
1Measurement, Analysis, Visualization of Internet
Topology, Workload, Performance and Routing
- CAIDA Overview for NPACI AHM
- February 10,2000
- dmoore _at_ caida.org
- www.caida.org
2CAIDA
- Cooperative Association for Internet Data
Analysis (CAIDA) is a collaborative undertaking
to promote greater cooperation in the engineering
and maintenance of a robust, scalable global
Internet infrastructure - Created October 1997 with seed funds from NSF --
current funding from NSF, DARPA, CAIDA members - Based at University of Californias San Diego
Supercomputer Center -- distributed
staff/collaborators Dr. K.C. Claffy - PI
3current focus
- advancing the capacity to monitor, depict, and
predict traffic behavior on current and advanced
networks - developing deploying tools to better engineer
and operate networks and to identify traffic
anomalies in real time - skitter (active measurements performance,
topology) - coral cflowd (passive measurements)
- routing data
- outreach
4no dearth of activity
5active measurement skitter
- Goals
- dynamically discover/ depict network topology
(directed graphs rooted at sources) - correlate effects of BGP routing changes
- correlate path performance with specific events
- Daniel McRobb (UCSD/CAIDA) developer
Otter viz using Lucent (Cheswick/Burch) layout
algorithm
6skitter infrastructure-wide measurements
- 18 monitors
- 21K-35K (eventually 60K) destinations
- architecture
- parallel ICMP probes
- 52-byte packets
- kernel time stamping
- ssh / Kerberos
http//www.caida.org/Presentations/IEPG.9808/
7visualizations of connectivity / topology
colored by distance from source
www.caida.org/Tools/Skitter/viz/hal.html
colored by country-level domain www.caida.org/Tool
s/Otter/Skitter/Images/
8rtt performance
- path connectivity performance used in
assessing route stability and ISP performance (5
minute) - end2end performance rtt between source and
destination sites (10-20 pps) - h/w performance depicts nuances of specific h/w
OS (ms granularity)
9(No Transcript)
10(No Transcript)
11end2end performance
12rtt performance h/w
13research priorities...
- development of 3D visualizations
- enhancement and porting of the arts binary file
format library (storage of active, passive
routing data) - deployment of additional active passive
measurement hosts - correlation of active skitter data with passive
measurements -- Coral monitors and router flow
statistics (cflowd) - trend analysis and identification of further
measurement / analysis requirements
graphics.stanford.edu/papers/h3/
14additional forms of measurement passive
monitoring
- workload profiling (s/w h/w design,
architecture optimizing, capacity planning) - security
- performance analysis SLAs
- QOS assurance across ISPs
- accounting/billing
- tools netramet, netflow, cflowd, coral
- all require work!
15 coral ocXmon monitors
- coral - up to OC12 (OC48???) http//www.caida.org
/Tools/Coral - persistent, real-time, full-frame traffic
collection - dynamic packet filtering triggered by attack
precursors - security policy compliance auditing (passive)
- security policy enforcement (active)
- need
- tcpdump and analysis extensions
- policy enforcement features
- address privacy issues
16cflowd flow-export analysis software
- Cisco routers (cflowd) - up to OC3 speeds
http//www.caida.org/Tools/Cflowd - used primarily for capacity planning and trend
analysis - AS-to-AS matrices
- net-to-net matrices
- port and protocol tables
- forward IP path
- measurement specification http//www.caida.org/Doc
s/meas_spec.html
17cflowd flow format collector
18 analysis for peering capacity planning
www.caida.org/Tools/Cflowd www.caida.org/Tools/Cor
al
19traffic analysis current future networks
http//www.caida.org/Learn/PrefixLength
http//www.caida.org/Learn/Favoritism/
20security via passive monitoring
- drivers
- backbone b/w increasing faster than host i/o
- new protocol deployment introduces unexpected
vulnerabilities - ATM limits access to higher-level protocol info
- IPsec good news bad news
- tools coral cflowd
- SDSC/PICS collaborator
21Manta
- manta displays the geographical placement of
Mbone infrastructure using data from the mwatch
mrinfo utilities - otter displays topological views of the multicast
infrastructure
http//www.caida.org/Tools/Manta
22mbone colored by metrics
23otter multipurpose viz tool
manual or semi geographic placement
algorithms http//www.caida.org/Tools/Otter/
24Cooperative Association for Internet Data
Analysis (CAIDA)University of Californias San
Diego Supercomputer Centerhttp//www.caida.org