KNOM Tutorial Internet Traffic Matrix Measurement and Analysis. Sue Bok Moon Dept. of Computer Science

Size: px
Start display at page:

Download "KNOM Tutorial Internet Traffic Matrix Measurement and Analysis. Sue Bok Moon Dept. of Computer Science"

Transcription

1 KNOM Tutorial 2003 Internet Traffic Matrix Measurement and Analysis Sue Bok Moon Dept. of Computer Science

2 Overview Definition of Traffic Matrix 4Traffic demand, delay, loss Applications of Traffic Matrix 4Engineering, research, SLAs Challenges in Obtaining Traffic Matrix 4Limitation of NetFlow and active probes 4Challenges in measurement and modeling Summay & Future Work 2

3 Definition of Traffic Matrix What is a traffic matrix? 4A matrix built on metric of interest 4Traffic demand matrix How much traffic flows from point A to point B Granularity: PoP, router, link, prefix 4Delay matrix How much delay from point A to point B Granularity: PoP, router, link, end hosts 4Loss matrix How many packets are dropped from point A to point B Granularity: PoP, router, end hosts 3

4 Example : AT&T Latency Matrix CAM CHI DAL DEN LA NY ATL CAM CHI Current Average : 35 msec DAL DEN LA 61 NY Latency in milliseconds 4

5 Traffic Demand Matrix Not part of SLAs 4Hard to obtain 4Few available publicly 5

6 Delay Matrix Usually a matrix of average delay of pings between routers of random selection per PoP 4Average of all PoP-to-PoP delays => SLA At end hosts 4Easy to get using pings between hosts of interest 6

7 Loss Matrix Usually a matrix of average loss rate of pings between routers of random selection per PoP 4Average of all PoP-to-PoP loss rates => SLA At end hosts 4Easy to get using pings between hosts of interest 7

8 Applications of Traffic Matrix Marketing/Sales 4How much traffic does customer A send from point #1 to point #2? Where should customer A buy more capacity from us? 4Is most traffic originating in Korea stay within Korea? What is the trend in international traffic growth? 4What is the performance that customer A sees? Do we have an edge over our competitors? 8

9 Applications of Traffic Matrix Network Operators 4Capacity Planning How much traffic do we have from point A to point B? How much capacity should we add? When should we add more capacity? 4Network Engineering Where is the hot spot? From SNMP What if a link fails from point A to point B? What if we move traffic from point A to point B? 9

10 Applications of Traffic Matrix Customers: SLAs 4What quality of service am I getting? How much delay do I get from ISP A? How much loss do I experience from ISP A? Can I get delay under X ms from ISP A? What is the most popular destination of my traffic? 10

11 Applications of Traffic Matrix Researchers 4Traffic modeling How does TM evolve over time? What is the fanout factor of traffic? How much more capacity do we expect between point A and point B? 4Example: IP over WDM Given physical topology of routers and optical nodes, what is the best virtual topology? Based on traffic demand matrix 11

12 Challenges in Obtaining Traffic Matrix Traffic Demand Matrix 4resource requirements in routers # of concurrently active flows 4resource requirements in measurement infrastructure production rate of flow statistics 4traffic characterization packet/byte rate of original traffic rate o f occurrence of original flows average packet/bytes per original flow 12

13 Resource Requirements Router Memory Resource in Measurement Infrastructure Server NetFlow data Analysis Resource in Router Fast link Traffic reports Network Network Operation Center 13

14 Most Popular Tools of Choice? NetFlow for traffic demand matrix ping for delay and loss matrix 14

15 NetFlow Cisco s proprietary tool 4Not an IETF standard Basic idea 4Based on (src ip, src port, dst ip, dst port, proto) 4Records byte/packet/duration per flow 4Cannot keep up with high speed links 4Can sample every N th packet 15

16 NetFlow Sampling Original Packets time flow #1 flow #2 flow #3 Sampled Packets (every 1/N, N=3) time 16

17 Limitation of NetFlow Scalability 4Historically NetFlow had a performance issue 4Never deployed at the core 4Number of flows in case of DDoS attacks beyond capacity Network melt down 17

18 Number of Active Flows on a OC-48 Link 18

19 Limitation of NetFlow Representativeness 4Can we estimate # of total flows from # of sampled flows accurately? 4Can we estimate # of total WWW flows from # of sampled WWW flows accurately? 4Metrics of interest: # of flows, flow rate, 4Packet sampling reduce effective packet rate save cost: slower memory sufficient (DRAM vs SRAM) 19

20 NetFlow Sampling Original Packets time flow #1 flow #2 flow #3 Sampled Packets (every 1/N, N=3) Flow Splitting time 20

21 Comparison of sparse and non-sparse applications Flow definition 45-tuple = (src ip, src port, dst ip, dst port, proto) 4interflow timeout = T Increase timeout T 4potentially less splitting 4fewer measured flows, more active flows Sparse vs. non-sparse flows 4napster vs. www 4# of mean active flows change differently over T 4No simple model of rate and # active flows based on aggregate traffic rates 4Model sparse and non-sparse flows separately [Duffield03] 21

22 Challenges in Delay Monitoring Not much is known about delay within ISP 4People think they know delay, but... 4Cisco SAA implementation on GSR did not consider clock synchronization, and outputs meaningless numbers Too many paths to cover 4hop-by-hop addition not yet possible 22

23 Limitation of Active Probes Representativeness [Choi04] 4Average? Median? 23

24 Suitable Statistic: Percentile! Min Med Avg Mode detection is hard 4 Difficult to distinguish small from big 4 Don t know how many ahead of them High-percentile 4 represents upper bound for most delay 4 requires a very small number of probes to estimate 99% percentile 24

25 Sampling for Demand Matrix Periodic sampling does not answer: 4What are the top 10 flows? 4What is the most dominant application and who is the heaviest user? 4What is the total # of packet for every flow? 25

26 Hash Function Mapping from a very large space to a smaller space 4h: X Y where X >> Y 4IP address to 10-bit hashed key 45-tuple address to 30-bit hashed key Load factor = collision probability 26

27 What are the top 10 flows? 27

28 Sampling for Elephants [Estan02] All packets Every n-th packet Update entry or create a new one Large flow memory Update existing entry Has entry? no Pass with p ~ size create new entry Small flow memory 28

29 Sampling for Elephants [Estan02] h1 h2 h3 All Large? Flow Memory 29

30 What is the most dominant application and who is the heaviest user? 30

31 Who is using my link? [Estan03] 31

32 Looking at the traffic Too much data for a human Do something smarter! 32

33 Looking at traffic aggregates Src. Dest. IP IP Src. Dest. net Dest. Source IPport Dest. Protoc ol Src. port net netran Destination IP Traffic Aggregating on kindividual packet header fields Ran Source Traffi gives useful results but Which Ran jeff.dorm.bigu.e Destination 11.9% Traffic 4 Traffic reports 1k are not Web port Where network du network always at the right 42.1 cdoes the uses granularity (e.g. individual IP address, subnet, traffic etc.) web come 12 Kazaa 4 Cannot show aggregates tracy.dorm.bigu. library.bigu.edu 6.7% % and from? which defined over one multiple kazaa? 3.12% 27.5% 3 Ssh fields (e.g. which network 2 uses 6.3% cs.bigu.edu which application) 18.1% The traffic analysis 3 tool risc.cs.bigu.edu dorm.bigu.edu should automatically 2.83% 17.8% find aggregates over the Most right fields traffic at goes the right granularity to the dorms Dest. port What apps are used? 33

34 Ideal traffic report Traffic aggregate Web traffic Web traffic to library.bigu.edu Web traffic from ICMP traffic from sloppynet.badu.edu to jeff.dorm.bigu.edu Traffic 42.1% 26.7% 13.4% 11.9% Web is the dominant This The paper library application is This about That s a is heavy a giving Denial the of network administrator a big flash user of Service insightful web attack traffic!! reports crowd! 34

35 Traffic Clusters and Reports Traffic clusters are multidimentional aggregates. Traffic reports give volume of chosen clusters Only those over threshold are reported To avoid redundant data, compress inferrable data (up to error H) Highlight non-obvious aggregates with unexpectedness label 35

36 Structure of regular traffic mix Backups from CAIDA to tape server SD-NAP 4Semi-regular time pattern FTP from SLAC Stanford SD-NAP Scripps web traffic Web & Squid servers Large ssh traffic Steady ICMP probing from CAIDA 36

37 What is the total # of packet of every flow? 37

38 Space-Code Bloom Filter Bloom filter answers set-membership. Space-code bloom filter answers multisetmembership Use a number of virtual Bloom-filters, spread multiplicity information over space. Write-only At OC768, it can work at 5ns SRAM What about storage space at the router? 38

39 Future Work One traffic matrix to rule? 4Can we answer all questions with one matrix? Continuous monitoring 4data export in real-time 4query over streaming data Availability/survivability 4Impliations in SLAs? 39

40 Failures are part of everyday operations Weekly Daily Hourly 40

41 Time between Failures (network-wide) 43%: <1 min 81%: <20 min 41

42 Sources of failures Duration can provide hints, e.g., 4long (>1hour): fiber cuts, severe failures 4medium (>10min): router/line card failures 4short (>1min): line card resets 4very short (<1min): software problems, optical equipment glitches Other hints 4shared equipment (routers, optical) 4 router logs (e.g., SONET alarms), etc. 42

43 Network-wide Failure Duration cumulative fraction of failures 40 % in 1-60sec 40 % in 1-15min 10 % in 15-60min 10 % >1h 43

44 References [Duffield03] N. Duffield, C. Lund, M. Thorup, Properties and Prediction of Flow Properties from Sampled Packet Streams, ACM SIGCOMM IMC, Miami, Oct., 2003 [Choi04] B.Y. Choi, S. Moon, Z.L. Zhang, C. Diot, Analysis of Point-to-Point Packet Delay in an Operational Network, IEEE INFOCOM, Hong Kong, Mar., 2004 [Estan03] C. Estan, S. Savage, G. Varghese, Automatically Inferring Patterns of Resource Consumption in Network Traffic, SIGCOMM 2003 [Estan02] C. Estan, G. Varghese, New Directions in Traffic Measurement and Accounting, SIGCOMM

45 Acknowledgements C. Estan s SIGCOMM 2002 talk. S. Bhattacharyya and G. Iannaconne s ICNP 2003 Tutorial. 45

AutoFocus: A Tool for Automatic Traffic Analysis. Cristian Estan, University of California, San Diego

AutoFocus: A Tool for Automatic Traffic Analysis. Cristian Estan, University of California, San Diego AutoFocus: A Tool for Automatic Traffic Analysis Cristian Estan, University of California, San Diego Who is using my link? October 2003 AutoFocus - NANOG 29 2 Informal problem definition Gigabytes of measurement

More information

MAD 12 Monitoring the Dynamics of Network Traffic by Recursive Multi-dimensional Aggregation. Midori Kato, Kenjiro Cho, Michio Honda, Hideyuki Tokuda

MAD 12 Monitoring the Dynamics of Network Traffic by Recursive Multi-dimensional Aggregation. Midori Kato, Kenjiro Cho, Michio Honda, Hideyuki Tokuda MAD 12 Monitoring the Dynamics of Network Traffic by Recursive Multi-dimensional Aggregation Midori Kato, Kenjiro Cho, Michio Honda, Hideyuki Tokuda 1 Background Traffic monitoring is important to detect

More information

New Directions in Traffic Measurement and Accounting. Need for traffic measurement. Relation to stream databases. Internet backbone monitoring

New Directions in Traffic Measurement and Accounting. Need for traffic measurement. Relation to stream databases. Internet backbone monitoring New Directions in Traffic Measurement and Accounting C. Estan and G. Varghese Presented by Aaditeshwar Seth 1 Need for traffic measurement Internet backbone monitoring Short term Detect DoS attacks Long

More information

Counter Braids: A novel counter architecture

Counter Braids: A novel counter architecture Counter Braids: A novel counter architecture Balaji Prabhakar Balaji Prabhakar Stanford University Joint work with: Yi Lu, Andrea Montanari, Sarang Dharmapurikar and Abdul Kabbani Overview Counter Braids

More information

Reformulating the monitor placement problem: Optimal Network-wide Sampling

Reformulating the monitor placement problem: Optimal Network-wide Sampling Reformulating the monitor placement problem: Optimal Network-wide Sampling Gion-Reto Cantieni (EPFL) Gianluca Iannaconne (Intel) Chadi Barakat (INRIA Sophia Antipolis) Patrick Thiran (EPFL) Christophe

More information

Power of Slicing in Internet Flow Measurement. Ramana Rao Kompella Cristian Estan

Power of Slicing in Internet Flow Measurement. Ramana Rao Kompella Cristian Estan Power of Slicing in Internet Flow Measurement Ramana Rao Kompella Cristian Estan 1 IP Network Management Network Operator What is happening in my network? How much traffic flows towards a given destination?

More information

Deliverable 1.1.6: Finding Elephant Flows for Optical Networks

Deliverable 1.1.6: Finding Elephant Flows for Optical Networks Deliverable 1.1.6: Finding Elephant Flows for Optical Networks This deliverable is performed within the scope of the SURFnet Research on Networking (RoN) project. These deliverables are partly written

More information

Lecture 19: Network Layer Routing in the Internet

Lecture 19: Network Layer Routing in the Internet Lecture 19: Network Layer Routing in the Internet COMP 332, Spring 2018 Victoria Manfredi Acknowledgements: materials adapted from Computer Networking: A Top Down Approach 7 th edition: 1996-2016, J.F

More information

Data Streaming Algorithms for Efficient and Accurate Estimation of Flow Size Distribution

Data Streaming Algorithms for Efficient and Accurate Estimation of Flow Size Distribution Data Streaming Algorithms for Efficient and Accurate Estimation of Flow Size Distribution Jun (Jim) Xu Networking and Telecommunications Group College of Computing Georgia Institute of Technology Joint

More information

A configuration-only approach to shrinking FIBs. Prof Paul Francis (Cornell)

A configuration-only approach to shrinking FIBs. Prof Paul Francis (Cornell) A configuration-only approach to shrinking FIBs Prof Paul Francis (Cornell) 1 Virtual Aggregation An approach to shrinking FIBs (and RIBs) In routers, not in route reflectors Works with legacy routers

More information

Counter Braids: A novel counter architecture

Counter Braids: A novel counter architecture Counter Braids: A novel counter architecture Balaji Prabhakar Balaji Prabhakar Stanford University Joint work with: Yi Lu, Andrea Montanari, Sarang Dharmapurikar and Abdul Kabbani Overview Counter Braids

More information

INTERNET TRAFFIC MEASUREMENT (PART II) Gaia Maselli

INTERNET TRAFFIC MEASUREMENT (PART II) Gaia Maselli INTERNET TRAFFIC MEASUREMENT (PART II) Gaia Maselli maselli@di.uniroma1.it Prestazioni dei sistemi di rete 2 Overview Basic concepts Characterization of traffic properties that are important to measure

More information

Expeditus: Congestion-Aware Load Balancing in Clos Data Center Networks

Expeditus: Congestion-Aware Load Balancing in Clos Data Center Networks Expeditus: Congestion-Aware Load Balancing in Clos Data Center Networks Peng Wang, Hong Xu, Zhixiong Niu, Dongsu Han, Yongqiang Xiong ACM SoCC 2016, Oct 5-7, Santa Clara Motivation Datacenter networks

More information

An overview on Internet Measurement Methodologies, Techniques and Tools

An overview on Internet Measurement Methodologies, Techniques and Tools An overview on Internet Measurement Methodologies, Techniques and Tools AA 2011/2012 emiliano.casalicchio@uniroma2.it (Agenda) Lezione 2/05/2012 Part 1 Intro basic concepts ISP Traffic exchange (peering)

More information

IBM Aurora Flow-Based Network Profiling System

IBM Aurora Flow-Based Network Profiling System IBM Aurora Flow-Based Network Profiling System Technical Aspects http://www.zurich.ibm.com/aurora/ Email: Jeroen Massar SwiNOG #15 4 December 2007 www.zurich.ibm.com/aurora

More information

BGP Routing inside an AS

BGP Routing inside an AS Hot Potatoes Heat Up BGP Routing Renata Teixeira (UC San Diego) http://www-cse.ucsd.edu/~teixeira with Aman Shaikh (AT&T), Tim Griffin(Intel), and Jennifer Rexford(AT&T) 30 th NANOG Miami, Florida BGP

More information

Flow Measurement. For IT, Security and IoT/ICS. Pavel Minařík, Chief Technology Officer EMITEC, Swiss Test and Measurement Day 20 th April 2018

Flow Measurement. For IT, Security and IoT/ICS. Pavel Minařík, Chief Technology Officer EMITEC, Swiss Test and Measurement Day 20 th April 2018 Flow Measurement For IT, Security and IoT/ICS Pavel Minařík, Chief Technology Officer EMITEC, Swiss Test and Measurement Day 20 th April 2018 What is Flow Data? Modern method for network monitoring flow

More information

Lecture 10.1 A real SDN implementation: the Google B4 case. Antonio Cianfrani DIET Department Networking Group netlab.uniroma1.it

Lecture 10.1 A real SDN implementation: the Google B4 case. Antonio Cianfrani DIET Department Networking Group netlab.uniroma1.it Lecture 10.1 A real SDN implementation: the Google B4 case Antonio Cianfrani DIET Department Networking Group netlab.uniroma1.it WAN WAN = Wide Area Network WAN features: Very expensive (specialized high-end

More information

Information, Gravity, and Traffic Matrices

Information, Gravity, and Traffic Matrices Information, Gravity, and Traffic Matrices Yin Zhang, Matthew Roughan, Albert Greenberg, Nick Duffield, David Donoho 1 Problem Have link traffic measurements Want to know demands from source to destination

More information

Trisul Network Analytics - Traffic Analyzer

Trisul Network Analytics - Traffic Analyzer Trisul Network Analytics - Traffic Analyzer Using this information the Trisul Network Analytics Netfllow for ISP solution provides information to assist the following operation groups: Network Operations

More information

This chapter provides information to configure Cflowd.

This chapter provides information to configure Cflowd. Cflowd In This Chapter This chapter provides information to configure Cflowd. Topics in this chapter include: Cflowd Overview on page 564 Operation on page 565 Cflowd Filter Matching on page 569 Cflowd

More information

Click to edit Master title style

Click to edit Master title style Click to edit Master title style SCALING NETWORK MONITORING IN A LARGE ENTERPRISE BroCon 2016 Austin, TX Click to edit Master Who title am style I? I work for Amazon s Worldwide Consumer Information Security

More information

CSCD 443/533 Advanced Networks

CSCD 443/533 Advanced Networks CSCD 443/533 Advanced Networks Lecture 10 Usage and Network Measurement Spring 2016 Reading: See References at end 1 Topics Internet Usage Measurement overview Why measure? What to measure? Where to measure?

More information

Level 3 SM Enhanced Management - FAQs. Frequently Asked Questions for Level 3 Enhanced Management

Level 3 SM Enhanced Management - FAQs. Frequently Asked Questions for Level 3 Enhanced Management Level 3 SM Enhanced Management - FAQs Frequently Asked Questions for Level 3 Enhanced Management 2015 Level 3 Communications, LLC. All rights reserved. 1 LAYER 3: CONVERGED SERVICES 5 Where can I find

More information

Three interface Router without NAT Cisco IOS Firewall Configuration

Three interface Router without NAT Cisco IOS Firewall Configuration Three interface Router without NAT Cisco IOS Firewall Configuration Document ID: 13893 Contents Introduction Prerequisites Requirements Components Used Conventions Configure Network Diagram Configurations

More information

Network traffic characterization

Network traffic characterization Network traffic characterization A historical perspective 1 Incoming AT&T traffic by port (18 hours of traffic to AT&T dial clients on July 22, 1997) Name port % bytes %packets bytes per packet world-wide-web

More information

Network traffic characterization. A historical perspective

Network traffic characterization. A historical perspective Network traffic characterization A historical perspective 1 Incoming AT&T traffic by port (18 hours of traffic to AT&T dial clients on July 22, 1997) Name port %bytes %packets bytes per packet world-wide-web

More information

Monitoring and Analysis

Monitoring and Analysis CHAPTER 3 Cisco Prime Network Analysis Module 5.1 has two types of dashboards: One type is the summary views found under the Monitor menu, and the other type is the over time views found under the Analyze

More information

A Framework for Efficient Class-based Sampling

A Framework for Efficient Class-based Sampling A Framework for Efficient Class-based Sampling Mohit Saxena and Ramana Rao Kompella Department of Computer Science Purdue University West Lafayette, IN, 47907 Email: {msaxena,kompella}@cs.purdue.edu Abstract

More information

On low-latency-capable topologies, and their impact on the design of intra-domain routing

On low-latency-capable topologies, and their impact on the design of intra-domain routing On low-latency-capable topologies, and their impact on the design of intra-domain routing Nikola Gvozdiev, Stefano Vissicchio, Brad Karp, Mark Handley University College London (UCL) We want low latency!

More information

Estimating Persistent Spread in High-speed Networks Qingjun Xiao, Yan Qiao, Zhen Mo, Shigang Chen

Estimating Persistent Spread in High-speed Networks Qingjun Xiao, Yan Qiao, Zhen Mo, Shigang Chen Estimating Persistent Spread in High-speed Networks Qingjun Xiao, Yan Qiao, Zhen Mo, Shigang Chen Southeast University of China University of Florida Motivation for Persistent Stealthy Spreaders Imagine

More information

Dynamics of Hot-Potato Routing in IP Networks

Dynamics of Hot-Potato Routing in IP Networks Dynamics of Hot-Potato Routing in IP Networks Jennifer Rexford AT&T Labs Research http://www.research.att.com/~jrex Joint work with Renata Teixeira (UCSD), Aman Shaikh (AT&T), and Timothy Griffin (Intel)

More information

Configuring Cisco IOS IP SLAs Operations

Configuring Cisco IOS IP SLAs Operations CHAPTER 50 This chapter describes how to use Cisco IOS IP Service Level Agreements (SLAs) on the switch. Cisco IP SLAs is a part of Cisco IOS software that allows Cisco customers to analyze IP service

More information

ALCATEL Edge Services Router

ALCATEL Edge Services Router ALCATEL 7420 Edge Services Router Alcatel builds next generation networks, delivering integrated end-to-end voice and data networking solutions to established and new carriers, as well as enterprises and

More information

Configuring Cisco IOS IP SLA Operations

Configuring Cisco IOS IP SLA Operations CHAPTER 58 This chapter describes how to use Cisco IOS IP Service Level Agreements (SLA) on the switch. Cisco IP SLA is a part of Cisco IOS software that allows Cisco customers to analyze IP service levels

More information

Accurate and Efficient SLA Compliance Monitoring

Accurate and Efficient SLA Compliance Monitoring Accurate and Efficient SLA Compliance Monitoring Joel Sommers Paul Barford Nick Duffield Amos Ron University of Wisconsin-Madison / Colgate University University of Wisconsin-Madison AT&T Labs- Research

More information

Lecture 2: Streaming Algorithms for Counting Distinct Elements

Lecture 2: Streaming Algorithms for Counting Distinct Elements Lecture 2: Streaming Algorithms for Counting Distinct Elements 20th August, 2008 Streaming Algorithms Streaming Algorithms Streaming algorithms have the following properties: 1 items in the stream are

More information

Quantifying Internet End-to-End Route Similarity

Quantifying Internet End-to-End Route Similarity Quantifying Internet End-to-End Route Similarity Ningning Hu and Peter Steenkiste Carnegie Mellon University Pittsburgh, PA 523, USA {hnn, prs}@cs.cmu.edu Abstract. Route similarity refers to the similarity

More information

Deriving Traffic Demands for Operational IP Networks: Methodology and Experience

Deriving Traffic Demands for Operational IP Networks: Methodology and Experience Deriving Traffic Demands for Operational IP Networks: Methodology and Experience Anja Feldmann University of Saarbrücken Albert Greenberg, Carsten Lund, Nick Reingold, Jennifer Rexford, and Fred True Internet

More information

The UCSD Network Telescope

The UCSD Network Telescope The UCSD Network Telescope Colleen Shannon cshannon @ caida.org NSF CIED Site Visit November 22, 2004 UCSD CSE Motivation Blocking technologies for automated exploits is nascent and not widely deployed

More information

From Routing to Traffic Engineering

From Routing to Traffic Engineering 1 From Routing to Traffic Engineering Robert Soulé Advanced Networking Fall 2016 2 In the beginning B Goal: pair-wise connectivity (get packets from A to B) Approach: configure static rules in routers

More information

CS 43: Computer Networks Internet Routing. Kevin Webb Swarthmore College November 14, 2013

CS 43: Computer Networks Internet Routing. Kevin Webb Swarthmore College November 14, 2013 CS 43: Computer Networks Internet Routing Kevin Webb Swarthmore College November 14, 2013 1 Reading Quiz Hierarchical routing Our routing study thus far - idealization all routers identical network flat

More information

Network Data Streaming A Computer Scientist s Journey in Signal Processing

Network Data Streaming A Computer Scientist s Journey in Signal Processing Network Data Streaming A Computer Scientist s Journey in Signal Processing Jun (Jim) Xu Networking and Telecommunications Group College of Computing Georgia Institute of Technology Joint work with: Abhishek

More information

Configure IP SLA Tracking for IPv4 Static Routes on an SG550XG Switch

Configure IP SLA Tracking for IPv4 Static Routes on an SG550XG Switch Configure IP SLA Tracking for IPv4 Static Routes on an SG550XG Switch Introduction When using static routing, you may experience a situation where a static route is active, but the destination network

More information

Tracing the Path to YouTube -

Tracing the Path to YouTube - Tracing the Path to YouTube - A Quantification of Path Lengths and Latencies towards Accepted for publication in IEEE Communications Magazine (Pre-print: http://in.tum.de/~doan/2018-yt-traces.pdf) Trinh

More information

Building Core Networks and Routers in the 2002 Economy

Building Core Networks and Routers in the 2002 Economy Building Core Networks and Routers in the 2002 Economy June, 2002 David Ward Cisco Systems, Inc. (mailto:dward@cisco.com) 1 Internet Backbone Growth Key Inflections & Trends 10000 5120 Technology Milestone

More information

Experiences with IPFIX-based Traffic Measurement for IPv6 Networks. Nakjung Choi, Hyeongu Son*, Youngseok Lee* and Yanghee Choi

Experiences with IPFIX-based Traffic Measurement for IPv6 Networks. Nakjung Choi, Hyeongu Son*, Youngseok Lee* and Yanghee Choi Experiences with IPFIX-based Traffic Measurement for IPv6 Networks Nakjung Choi, Hyeongu Son*, Youngseok Lee* and Yanghee Choi Seoul National Univ *Chungnam National Univ 27. 8. 31 (Fri) SIGCOMM 27 IPv6

More information

Network Awareness and Network Security

Network Awareness and Network Security Network Awareness and Network Security John McHugh Canada Research Chair in Privacy and Security Director, oratory Dalhousie University, Halifax, NS CASCON CyberSecurity Workshop 17 October 2005 Overview

More information

Real-Time and Resilient Intrusion Detection: A Flow-Based Approach

Real-Time and Resilient Intrusion Detection: A Flow-Based Approach Real-Time and Resilient Intrusion Detection: A Flow-Based Approach Rick Hofstede, Aiko Pras To cite this version: Rick Hofstede, Aiko Pras. Real-Time and Resilient Intrusion Detection: A Flow-Based Approach.

More information

CS 43: Computer Networks. 24: Internet Routing November 19, 2018

CS 43: Computer Networks. 24: Internet Routing November 19, 2018 CS 43: Computer Networks 24: Internet Routing November 19, 2018 Last Class Link State + Fast convergence (reacts to events quickly) + Small window of inconsistency Distance Vector + + Distributed (small

More information

Routing Metric. ARPANET Routing Algorithms. Problem with D-SPF. Advanced Computer Networks

Routing Metric. ARPANET Routing Algorithms. Problem with D-SPF. Advanced Computer Networks Advanced Computer Networks Khanna and Zinky, The Revised ARPANET Routing Metric, Proc. of ACM SIGCOMM '89, 19(4):45 46, Sep. 1989 Routing Metric Distributed route computation is a function of link cost

More information

Lecture 13: Traffic Engineering

Lecture 13: Traffic Engineering Lecture 13: Traffic Engineering CSE 222A: Computer Communication Networks Alex C. Snoeren Thanks: Mike Freedman, Nick Feamster Lecture 13 Overview Evolution of routing in the ARPAnet Today s TE: Adjusting

More information

The Subspace Method for Diagnosing Network-Wide Traffic Anomalies. Anukool Lakhina, Mark Crovella, Christophe Diot

The Subspace Method for Diagnosing Network-Wide Traffic Anomalies. Anukool Lakhina, Mark Crovella, Christophe Diot The Subspace Method for Diagnosing Network-Wide Traffic Anomalies Anukool Lakhina, Mark Crovella, Christophe Diot What s happening in my network? Is my customer being attacked? probed? infected? Is there

More information

Configuring Cisco IOS IP SLAs Operations

Configuring Cisco IOS IP SLAs Operations CHAPTER 39 This chapter describes how to use Cisco IOS IP Service Level Agreements (SLAs) on the switch. Cisco IP SLAs is a part of Cisco IOS software that allows Cisco customers to analyze IP service

More information

Initial motivation: 32-bit address space soon to be completely allocated. Additional motivation:

Initial motivation: 32-bit address space soon to be completely allocated. Additional motivation: IPv6 Initial motivation: 32-bit address space soon to be completely allocated. Additional motivation: header format helps speed processing/forwarding header changes to facilitate QoS IPv6 datagram format:

More information

Counter Braids: A novel counter architecture

Counter Braids: A novel counter architecture Counter Braids: A novel counter architecture Balaji Prabhakar Balaji Prabhakar Stanford University Joint work with: Yi Lu, Andrea Montanari, Sarang Dharmapurikar and Abdul Kabbani Overview Counter Braids

More information

Effects of Internet Path Selection on Video-QoE

Effects of Internet Path Selection on Video-QoE Effects of Internet Path Selection on Video-QoE by Mukundan Venkataraman & Mainak Chatterjee Dept. of EECS University of Central Florida, Orlando, FL 32826 mukundan@eecs.ucf.edu mainak@eecs.ucf.edu Streaming

More information

Internet Architecture and Experimentation

Internet Architecture and Experimentation Internet Architecture and Experimentation Today l Internet architecture l Principles l Experimentation A packet switched network Modern comm. networks are packet switched Data broken into packets, packet

More information

precise rules that govern communication between two parties TCP/IP: the basic Internet protocols IP: Internet protocol (bottom level)

precise rules that govern communication between two parties TCP/IP: the basic Internet protocols IP: Internet protocol (bottom level) Protocols precise rules that govern communication between two parties TCP/IP: the basic Internet protocols IP: Internet protocol (bottom level) all packets shipped from network to network as IP packets

More information

Revealing the load-balancing behavior of YouTube traffic of interdomain links

Revealing the load-balancing behavior of YouTube traffic of interdomain links Revealing the load-balancing behavior of YouTube traffic of interdomain links Ricky K. P. Mok + Vaibhav Bajpai*, Amogh Dhamdhere +, kc claffy + + CAIDA/ University of California San Diego * Technical University

More information

measurement goals why traffic measurement of Internet is so hard? measurement needs combined skills diverse traffic massive volume of traffic

measurement goals why traffic measurement of Internet is so hard? measurement needs combined skills diverse traffic massive volume of traffic measurement goals Traffic Measurement and Analysis () SOI ASIA Lecture 22//26 Kenjiro Cho Sony Computer Science Labs, Inc. kjc@csl.sony.co.jp for operations trouble shooting diagnosis and tuning of performance,

More information

A Large Scale Simulation Study: Impact of Unresponsive Malicious Flows

A Large Scale Simulation Study: Impact of Unresponsive Malicious Flows A Large Scale Simulation Study: Impact of Unresponsive Malicious Flows Yen-Hung Hu, Debra Tang, Hyeong-Ah Choi 3 Abstract Researches have unveiled that about % of current Internet traffic is contributed

More information

Lecture 11: Packet forwarding

Lecture 11: Packet forwarding Lecture 11: Packet forwarding Anirudh Sivaraman 2017/10/23 This week we ll talk about the data plane. Recall that the routing layer broadly consists of two parts: (1) the control plane that computes routes

More information

A Configuration-only Approach to FIB Reduction. Paul Francis Hitesh Ballani, Tuan Cao Cornell

A Configuration-only Approach to FIB Reduction. Paul Francis Hitesh Ballani, Tuan Cao Cornell A Configuration-only Approach to FIB Reduction Paul Francis Hitesh Ballani, Tuan Cao Cornell Virtual Aggregation An approach to shrinking FIBs (and RIBs) In interface-card FIB, maybe control-card RIB Works

More information

Hot Potatoes Heat Up BGP Routing

Hot Potatoes Heat Up BGP Routing Hot Potatoes Heat Up BGP Routing Renata Teixeira Laboratoire d Informatique de Paris 6 Université Pierre et Marie Curie Amsterdam Internet Routing Architecture Verio AT&T AOL Web Server UCSD Sprint User

More information

Advanced Application Reporting USER GUIDE

Advanced Application Reporting USER GUIDE Advanced Application Reporting USER GUIDE CONTENTS 1.0 Preface: About This Document 5 2.0 Conventions 5 3.0 Chapter 1: Introducing Advanced Application Reporting 6 4.0 Features and Benefits 7 5.0 Product

More information

Advanced Network Design

Advanced Network Design Advanced Network Design Organization Whoami, Book, Wikipedia www.cs.uchicago.edu/~nugent/cspp54015 Grading Homework/project: 60% Midterm: 15% Final: 20% Class participation: 5% Interdisciplinary Course

More information

Abstraction-Driven Network Verification and Design (a personal odyssey) Geoffrey Xie Naval Postgraduate School

Abstraction-Driven Network Verification and Design (a personal odyssey) Geoffrey Xie Naval Postgraduate School Abstraction-Driven Network Verification and Design (a personal odyssey) Geoffrey Xie Naval Postgraduate School xie@nps.edu It started in 2004 A sabbatical at CMU Joined a collaborative project with AT&T

More information

Concept: Traffic Flow. Prof. Anja Feldmann, Ph.D. Dr. Steve Uhlig

Concept: Traffic Flow. Prof. Anja Feldmann, Ph.D. Dr. Steve Uhlig Concept: Traffic Flow Prof. Anja Feldmann, Ph.D. Dr. Steve Uhlig 1 Passive measurement capabilities: Packet monitors Available data: All protocol information All content Possible analysis: Application

More information

Design principles in parser design

Design principles in parser design Design principles in parser design Glen Gibb Dept. of Electrical Engineering Advisor: Prof. Nick McKeown Header parsing? 2 Header parsing? Identify headers & extract fields A???? B???? C?? Field Field

More information

Interdomain Routing Design for MobilityFirst

Interdomain Routing Design for MobilityFirst Interdomain Routing Design for MobilityFirst October 6, 2011 Z. Morley Mao, University of Michigan In collaboration with Mike Reiter s group 1 Interdomain routing design requirements Mobility support Network

More information

Internet Load Balancing Guide. Peplink Balance Series. Peplink Balance. Internet Load Balancing Solution Guide

Internet Load Balancing Guide. Peplink Balance Series. Peplink Balance. Internet Load Balancing Solution Guide Peplink Balance Internet Load Balancing Solution Guide http://www.peplink.com Copyright 2010 Peplink Internet Load Balancing Instant Improvement to Your Network Introduction Introduction Understanding

More information

Cisco Implementing Cisco IP Routing (ROUTE v2.0)

Cisco Implementing Cisco IP Routing (ROUTE v2.0) Cisco 300-101 Implementing Cisco IP Routing (ROUTE v2.0) https://killexams.com/pass4sure/exam-detail/300-101 QUESTION: 228 Refer to the exhibit. Which statement about this neighbor of R1 is true? A. OSPFv3

More information

Peer-to-Peer Networks

Peer-to-Peer Networks Peer-to-Peer Networks 14-740: Fundamentals of Computer Networks Bill Nace Material from Computer Networking: A Top Down Approach, 6 th edition. J.F. Kurose and K.W. Ross Administrivia Quiz #1 is next week

More information

CS 43: Computer Networks Internet Routing. Kevin Webb Swarthmore College November 16, 2017

CS 43: Computer Networks Internet Routing. Kevin Webb Swarthmore College November 16, 2017 CS 43: Computer Networks Internet Routing Kevin Webb Swarthmore College November 16, 2017 1 Hierarchical routing Our routing study thus far - idealization all routers identical network flat not true in

More information

Traffic Engineering with Estimated Traffic Matrices

Traffic Engineering with Estimated Traffic Matrices Traffic Engineering with Estimated Traffic Matrices Matthew Roughan Mikkel Thorup Yin Zhang www.research.att.com/~roughan www.research.att.com/~mthorup www.research.att.com/~yzhang Shannon Lab AT&T Research

More information

Machine-Learning-Based Flow scheduling in OTSSenabled

Machine-Learning-Based Flow scheduling in OTSSenabled Machine-Learning-Based Flow scheduling in OTSSenabled Datacenters Speaker: Lin Wang Research Advisor: Biswanath Mukherjee Motivation Traffic demand increasing in datacenter networks Cloud-service, parallel-computing,

More information

Video at the Edge passive delay measurements. Kathleen Nichols Pollere, Inc November 17, 2016

Video at the Edge passive delay measurements. Kathleen Nichols Pollere, Inc November 17, 2016 Video at the Edge passive delay measurements Kathleen Nichols Pollere, Inc nichols@pollere.net November 17, 2016 Talk Roadmap Netflix and YouTube network characterization delay profiles delay localization

More information

NetFlow Configuration Guide

NetFlow Configuration Guide Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION

More information

Outline. The demand The San Jose NAP. What s the Problem? Most things. Time. Part I AN OVERVIEW OF HARDWARE ISSUES FOR IP AND ATM.

Outline. The demand The San Jose NAP. What s the Problem? Most things. Time. Part I AN OVERVIEW OF HARDWARE ISSUES FOR IP AND ATM. Outline AN OVERVIEW OF HARDWARE ISSUES FOR IP AND ATM Name one thing you could achieve with ATM that you couldn t with IP! Nick McKeown Assistant Professor of Electrical Engineering and Computer Science

More information

Design of an IP Flow Record Query Language

Design of an IP Flow Record Query Language Design of an IP Flow Record Query Language Vladislav Marinov and Jürgen Schönwälder Computer Science, Jacobs University Bremen, Germany {v.marinov,j.schoenwaelder}@jacobs-university.de Abstract. Internet

More information

Master Course Computer Networks IN2097

Master Course Computer Networks IN2097 Chair for Network Architectures and Services Prof. Carle Department for Computer Science TU München Master Course Computer Networks IN2097 Chapter 7 - Network Measurements Introduction Architecture & Mechanisms

More information

Measurements for Network Operations

Measurements for Network Operations Measurements for Network Operations Jennifer Rexford Internet and Networking Systems AT&T Labs - Research; Florham Park, NJ http://www.research.att.com/~jrex Part 1: Outline Introduction Role of measurement

More information

ECEN 689 Special Topics in Data Science for Communications Networks

ECEN 689 Special Topics in Data Science for Communications Networks ECEN 689 Special Topics in Data Science for Communications Networks Nick Duffield Department of Electrical & Computer Engineering Texas A&M University Organization Instructor: Nick Duffield Contact: duffieldng

More information

Chapter 4: outline. Network Layer 4-1

Chapter 4: outline. Network Layer 4-1 Chapter 4: outline 4.1 introduction 4.2 virtual circuit and datagram networks 4.3 what s inside a router 4.4 IP: Internet Protocol datagram format IPv4 addressing ICMP IPv6 4.5 routing algorithms link

More information

CSC 4900 Computer Networks: Routing Protocols

CSC 4900 Computer Networks: Routing Protocols CSC 4900 Computer Networks: Routing Protocols Professor Henry Carter Fall 2017 Last Time Link State (LS) versus Distance Vector (DV) algorithms: What are some of the differences? What is an AS? Why do

More information

Master Course Computer Networks IN2097

Master Course Computer Networks IN2097 Chair for Network Architectures and Services Prof. Carle Department for Computer Science TU München Master Course Computer Networks IN2097 Prof. Dr.-Ing. Georg Carle Christian Grothoff, Ph.D. Dr. Nils

More information

IP SLAs Overview. Finding Feature Information. Information About IP SLAs. IP SLAs Technology Overview

IP SLAs Overview. Finding Feature Information. Information About IP SLAs. IP SLAs Technology Overview This module describes IP Service Level Agreements (SLAs). IP SLAs allows Cisco customers to analyze IP service levels for IP applications and services, to increase productivity, to lower operational costs,

More information

Lecture 14: Performance Architecture

Lecture 14: Performance Architecture Lecture 14: Performance Architecture Prof. Shervin Shirmohammadi SITE, University of Ottawa Prof. Shervin Shirmohammadi CEG 4185 14-1 Background Performance: levels for capacity, delay, and RMA. Performance

More information

CSE 123A Computer Networks

CSE 123A Computer Networks CSE 123A Computer Networks Winter 2005 Lecture 12 Internet Routing: Multicast Today: Multicast routing Multicast service model Host interface Host-router interactions (IGMP) Multicast Routing Limiters

More information

set active-probe (PfR)

set active-probe (PfR) set active-probe (PfR) set active-probe (PfR) To configure a Performance Routing (PfR) active probe with a forced target assignment within a PfR map, use the set active-probe command in PfR map configuration

More information

Scalable Streaming Analytics

Scalable Streaming Analytics Scalable Streaming Analytics KARTHIK RAMASAMY @karthikz TALK OUTLINE BEGIN I! II ( III b Overview Storm Overview Storm Internals IV Z V K Heron Operational Experiences END WHAT IS ANALYTICS? according

More information

Chapter 4: Network Layer. Lecture 12 Internet Routing Protocols. Chapter goals: understand principles behind network layer services:

Chapter 4: Network Layer. Lecture 12 Internet Routing Protocols. Chapter goals: understand principles behind network layer services: NET 331 Computer Networks Lecture 12 Internet Routing Protocols Dr. Anis Koubaa Reformatted slides from textbook Computer Networking a top-down appraoch, Fifth Edition by Kurose and Ross, (c) Pearson Education

More information

Cisco Express Forwarding Overview

Cisco Express Forwarding Overview Cisco Express Forwarding () is advanced, Layer 3 IP switching technology. optimizes network performance and scalability for networks with large and dynamic traffic patterns, such as the Internet, on networks

More information

vserver vserver virtserver-name no vserver virtserver-name Syntax Description

vserver vserver virtserver-name no vserver virtserver-name Syntax Description Chapter 2 vserver vserver To identify a virtual server, and then enter the virtual server configuration submode, use the vserver command. To remove a virtual server from the configuration, use the no form

More information

Computer Science 461 Final Exam May 22, :30-3:30pm

Computer Science 461 Final Exam May 22, :30-3:30pm NAME: Login name: Computer Science 461 Final Exam May 22, 2012 1:30-3:30pm This test has seven (7) questions, each worth ten points. Put your name on every page, and write out and sign the Honor Code pledge

More information

International Journal of Advance Engineering and Research Development. Simulation Based Improvement Study of Overprovisioned IP Backbone Network

International Journal of Advance Engineering and Research Development. Simulation Based Improvement Study of Overprovisioned IP Backbone Network Scientific Journal of Impact Factor (SJIF): 4.72 International Journal of Advance Engineering and Research Development Volume 4, Issue 8, August -2017 e-issn (O): 2348-4470 p-issn (P): 2348-6406 Simulation

More information

Overview of IPM. What is IPM? CHAPTER

Overview of IPM. What is IPM? CHAPTER CHAPTER 1 This chapter provides an overview of Cisco Internetwork Performance Monitor (IPM) application. It contains the following sections: What is IPM?, page 1-1 Key Terms and Concepts, page 1-3 How

More information

COMP211 Chapter 5 Network Layer: The Control Plane

COMP211 Chapter 5 Network Layer: The Control Plane COMP211 Chapter 5 Network Layer: The Control Plane All material copyright 1996-2016 J.F Kurose and K.W. Ross, All Rights Reserved Computer Networking: A Top Down Approach 7 th edition Jim Kurose, Keith

More information

DDoS Protection in Backbone Networks

DDoS Protection in Backbone Networks DDoS Protection in Backbone Networks The Czech Way Pavel Minarik, Chief Technology Officer Holland Strikes Back, 3 rd Oct 2017 Backbone DDoS protection Backbone protection is specific High number of up-links,

More information