Packet Sampling for Flow Accounting: Challenges and Limitations

Size: px
Start display at page:

Download "Packet Sampling for Flow Accounting: Challenges and Limitations"

Transcription

1 Packet Sampling for Flow Accounting: Challenges and Limitations Tanja Zseby (Fraunhofer FOKUS) Thomas Hirsch (Fraunhofer FOKUS) Benoit Claise (Cisco Systems) April 29, 2008 This work was funded by Cisco Systems as part of the VEGAS project.

2 Outline Problem statement Packet selection techniques Accuracy assessment in theory Accuracy assessment in practice Experimental results Standardization (IPFIX/PSAMP) Conclusion 2008 FhG FOKUS PAM of 20

3 Usage-based Accounting Accounting based on flow volume (transferred bytes) Requires flow measurements all packets from network A all packets with DSCP=x all VoIP packets Flow:= packets with common properties Customer Network Customer Network End System Provider Network 2008 FhG FOKUS PAM of 20

4 Flow Measurements Packets: <s 1, t 1, c 1 >, <s 2, t 2, c 2 >,... <s N, t N, c N > Packet Attributes at Observation Point s i, sequence number t i arrival time c i content (header, payload) Classification f(c i ) Flows: FlowID 1: <s 1, t 1, c 1 > <s 4, t 4, c 4 > <s 8, t 8, c 8 > FlowID 2: <s 2, t 2, c 2 > <s 3, t 3, c 3 > <s 6, t 6, c 6 > FlowID 3: <s 5, t 5, c 5 > <s 7, t 7, c 7 > <s 9, t 9, c 9 > Aggregation Aggregation Aggregation Flow Records: < N, μ, σ,... > < N, μ, σ,... > < N, μ, σ,... > f f f f f f f f f 2008 FhG FOKUS PAM of 20

5 Problem: Resource Consumption Resource Limitations Processing power Transmission Storage Demand depends on Data rates Required granularity Solutions Dedicated Hardware Improved Algorithms Data Selection Additional CPU load for running NetFlow on different routers* 1:100 *source: NetFlow Performance Analysis, Cisco white paper 2008 FhG FOKUS PAM of 20

6 Packet Selection Packets: Selected Packets: <s 1, t 1, c 1 >, <s 2, t 2, c 2 >,... <s N, t N, c N > f(c i ) Filtering Packet Selection f(s i ) or f(t i,) Sampling <s 2, t 2, c 2 >, <s 6, t 6, c 6 >... <s n, t n, c n > Classification Flows: FlowID 1: <s 8, t 8, c 8 > FlowID 2: <s 2, t 2, c 2 > <s 6, t 6, c 6 > FlowID 3: <s 5, t 5, c 5 > <s 9, t 9, c 9 > Aggregation Aggregation Aggregation Flow Records: < Nˆ, μˆ, σˆ,... > f f f < Nˆ, μˆ, σˆ,... > < Nˆ, μˆ, σˆ,... > f f f f f f 2008 FhG FOKUS PAM of 20

7 Packet Selection Techniques (Examples) 2008 FhG FOKUS PAM of 20

8 Problem: Accuracy Assessment Accuracy Assessment required Achievable accuracy depends on Sampling and estimation method Sampling parameters Population characteristics unknown and highly dynamic Accuracy assessment during measurement For each measurement interval For each flow Based on sampled data Bias Precision 2008 FhG FOKUS PAM of 20

9 Theoretical Model Case: n-out-of-n, sampling before classification Estimation of Flow Volume: Variance of Estimate: Sum ˆ f N n f = n i= 1 n x f 2 f [ ˆ N N V Sum ] = V[ x ] = V[ x ] f, i f f, i 2 f, i n i= 1 n i= 1 n random variables N Packets in MI n Packets in sample Sum f N f n f μ f 2 σ x x f f,i Volume in flow f Number of packets in flow f Sampled packets from flow f Mean packet size in flow f Packet size variance in flow f Bytes in i-th packet Estimation accuracy for flow f : StdErr rel ( ) 1 N N σ + μ N μ = N μ n N f f f f f f f Flow Characteristics: Number of packets from flow f in MI Packet size variance in flow f Packet size mean in flow f Sampling Parameters: Number of all packets in MI (population size) Number of selected packets in MI (sample size) 2008 FhG FOKUS PAM of 20

10 Accuracy Assessment in Practice Flow characteristics unknown Estimation from sampled data Storing per-packet information too costly Storing aggregates NetFlow Records Number of packets stored Sum of packet sizes stored Calculation/estimation of mean packet size possible BUT: calculation/estimation of packet size variance not possible NetFlow Records: N f, x f, 2 xf Store sum of squares! 2008 FhG FOKUS PAM of 20

11 1-in-K Sampling (Cisco) 1-in-K: Count-based stratification with equal allocation Packet selection limited to 1 packet per subinterval Theoretical Model see paper Stratification gain Depends on variance of packet sizes from flow f in strata 1 packet per sub-interval selected not sufficient to estimate variance in sub-interval n-out-of-n: 1 N 3 of 15 1-in-K: 1 K 1 K 1 K 2008 FhG FOKUS PAM x 1 of 5 11 of 20

12 Setup Experiments Traces from three different networks Different sampling schemes Different classification schemes Different measurement interval lengths Sampling before and after classification Accuracy Calculation based on theoretical model using real flow characteristics 2008 FhG FOKUS PAM of 20

13 Flow Characterstics Trace: CIRIL MI: 10M Classification S24D FhG FOKUS PAM of 20

14 Conformant Flows Sampling fraction: 5%, StdErr 0.05 Sampling after classification Sampling before classification 2008 FhG FOKUS PAM of 20

15 Sampling Experiments 1000 sampling runs per experiment Different sampling rates Calculation of bias and standard error Comparison of schemes n-out-of-n 1-in-K systematic 2008 FhG FOKUS PAM of 20

16 Conformant Flows Trace: NZIX MI: 1M Classification S24D00 Sampling fraction =5% Max rel. StdErr Error/CL n-of-n 1-in-K Systematic /99% /95% /99% /95% /95% /95% /95% /95% > FhG FOKUS PAM of 20

17 Results Comparison of schemes n-out-of-n close to n-out-of-n model 1-in-K close to n-out-of-n model Systematic sampling Better results for some flows But unpredictable (high variance of results) Differs from model Higher accuracy achievable with Larger sample fraction Longer observation periods (if flow characteristics remain) Coarse grained classification Aggregation of flows 2008 FhG FOKUS PAM of 20

18 IPFIX/PSAMP IEs IP Flow Information Export (IPFIX) Standard for flow information export (RFC5101) Information elements (RFC5102) Packet Sampling (PSAMP) Packet selection techniques (filtering, sampling) Packet export using IPFIX Parameter Number N of packets in measurement interval Number n of packets in sample Number of packets from flow f in sample Sum (bytes in sampled packets) Sum of squares (bytes in sampled packets) IPFIX/PSAMP IEs samplingpopulation samplingsize packettotalcount octettotalcount octettotalsumofsquares 2008 FhG FOKUS PAM of 20

19 Conclusion Accuracy Assessment in theory and practice n-out-of-n (before/after classification) store sum of squares 1-in-K not possible in practice (although model exists) Experiments Small flows poor accuracy for sampling before classification 1-in-K close to n-out-of-n Accuracy depends on settings (obs. period, classification) Alternative: Flow selection based on expected accuracy IPFIX provides required information elements Work in progress: Sampling for other metrics (e.g. for anomaly detection) Hash-based selection 2008 FhG FOKUS PAM of 20

20 Thank you! FOKUS Open Source IPFIX Library: Measurement data always welcome at:

Sampling Challenges. Tanja Zseby Competence Center Network Research Fraunhofer Institute FOKUS Berlin. COST TMA September 22, 2008

Sampling Challenges. Tanja Zseby Competence Center Network Research Fraunhofer Institute FOKUS Berlin. COST TMA September 22, 2008 Sampling Challenges Tanja Zseby Competence Center Network Research Fraunhofer Institute FOKUS Berlin Desired Features for Traffic Observation Network-wide: multiple observation points Flexible: change

More information

Master Course Computer Networks IN2097

Master Course Computer Networks IN2097 Chair for Network Architectures and Services Prof. Carle Department for Computer Science TU München Master Course Computer Networks IN2097 Chapter 7 - Network Measurements Introduction Architecture & Mechanisms

More information

Master Course Computer Networks IN2097

Master Course Computer Networks IN2097 Chair for Network Architectures and Services Prof. Carle Department for Computer Science TU München Master Course Computer Networks IN2097 Prof. Dr.-Ing. Georg Carle Christian Grothoff, Ph.D. Dr. Nils

More information

Presentation and Demo: Flow Valuations based on Network-Service Cooperation

Presentation and Demo: Flow Valuations based on Network-Service Cooperation Presentation and Demo: Flow Valuations based on Network-Service Cooperation Tanja Zseby, Thomas Hirsch Competence Center Network Research Fraunhofer Institute FOKUS, Berlin, Germany 1/25 2010, T. Zseby

More information

IP Multicast Traffic Measurement Method with IPFIX/PSAMP

IP Multicast Traffic Measurement Method with IPFIX/PSAMP IP Multicast Traffic Measurement Method with IPFIX/PSAMP Atsushi Kobayashi, Yutaka Hirokawa, and Haruhiko Nishida NTT Information Sharing Platform Laboratories 3-9-11 Midori-cho, Musashino, Tokyo 18-8585,

More information

Lightweight enhanced monitoring for high-speed networks

Lightweight enhanced monitoring for high-speed networks Lightweight enhanced monitoring for high-speed networks Rosa Vilardi, Dr. Luigi Alfredo Grieco, Prof. Gennaro Boggia Electrical and Information Engineering Department (DEI) Politecnico di Bari Italy Dr.

More information

Flow-based Accounting: Applications and Standardisation

Flow-based Accounting: Applications and Standardisation Flow-based Accounting: Applications and Standardisation SCAMPI Workshop May 3, 2004 Simon Leinen, SWITCH Flow-based Accounting - Basic Idea Classify packets into flows (equivalence classes)

More information

Passive One-Way-Delay Measurements and Data Export

Passive One-Way-Delay Measurements and Data Export Passive One-Way-Delay Measurements and Data Export Tanja Zseby, Lutz Mark, Carsten Schmoll, Guido Pohl Fraunhofer FOKUS Kaiserin-Augusta-Allee 31, 10589 Berlin, Germany {zseby, mark, schmoll, pohl}@fokus.fraunhofer.de

More information

Traffic Flow Measurements within IP Networks: Requirements, Technologies and Standardization

Traffic Flow Measurements within IP Networks: Requirements, Technologies and Standardization Traffic Flow Measurements within IP Networks: Requirements, Technologies and Standardization Jürgen Quittek NEC Europe Ltd., Network Laboratories, Heidelberg, Germany Tanya Szeby, Georg Carle, Sebastian

More information

IP Multicast Traffic Measurement Method with IPFIX/PSAMP. Atsushi Kobayashi Yutaka Hirokawa Haruhiko Nishida NTT

IP Multicast Traffic Measurement Method with IPFIX/PSAMP. Atsushi Kobayashi Yutaka Hirokawa Haruhiko Nishida NTT IP Multicast Traffic Measurement Method with /PSAMP Atsushi Kobayashi Yutaka Hirokawa Haruhiko Nishida NTT 1 Outline Introduction Motivation Requirements Main requirements for measurement system in largescale

More information

Internet Engineering Task Force (IETF) Category: Standards Track. J. Quittek. NEC Europe Ltd. October 2012

Internet Engineering Task Force (IETF) Category: Standards Track. J. Quittek. NEC Europe Ltd. October 2012 Internet Engineering Task Force (IETF) Request for Comments: 6727 Category: Standards Track ISSN: 2070-1721 T. Dietz, Ed. NEC Europe Ltd. B. Claise Cisco Systems, Inc. J. Quittek NEC Europe Ltd. October

More information

Adaptation of Real-time Temporal Resolution for Bitrate Estimates in IPFIX Systems

Adaptation of Real-time Temporal Resolution for Bitrate Estimates in IPFIX Systems Adaptation of Real-time Temporal Resolution for Bitrate Estimates in IPFIX Systems Rosa Vilardi, Luigi Alfredo Grieco, Gennaro Boggia DEE - Politecnico di Bari - Italy Email: {r.vilardi, a.grieco, g.boggia}@poliba.it

More information

Network Working Group. Category: Informational Hitachi Europe N. Brownlee CAIDA B. Claise Cisco Systems, Inc. March 2009

Network Working Group. Category: Informational Hitachi Europe N. Brownlee CAIDA B. Claise Cisco Systems, Inc. March 2009 Network Working Group Request for Comments: 5472 Category: Informational T. Zseby Fraunhofer FOKUS E. Boschi Hitachi Europe N. Brownlee CAIDA B. Claise Cisco Systems, Inc. March 2009 Status of This Memo

More information

Configuring Application Visibility and Control for Cisco Flexible Netflow

Configuring Application Visibility and Control for Cisco Flexible Netflow Configuring Application Visibility and Control for Cisco Flexible Netflow First published: July 22, 2011 This guide contains information about the Cisco Application Visibility and Control feature. It also

More information

SCRIPT: An Architecture for IPFIX Data Distribution

SCRIPT: An Architecture for IPFIX Data Distribution SCRIPT Public Workshop January 20, 2010, Zurich, Switzerland SCRIPT: An Architecture for IPFIX Data Distribution Peter Racz Communication Systems Group CSG Department of Informatics IFI University of Zürich

More information

End-to-End Flow Monitoring with IPFIX

End-to-End Flow Monitoring with IPFIX End-to-End Flow Monitoring with IPFIX Byungjoon Lee 1, Hyeongu Son 2, Seunghyun Yoon 1 and Youngseok Lee 2 1 ETRI, NCP Team, Gajeong-Dong 161, Yuseong-Gu, Daejeon, Republic of Korea {bjlee, shpyoon}@etri.re.kr

More information

Cisco Call Management Records Field Descriptions

Cisco Call Management Records Field Descriptions CHAPTER 8 Cisco Call Management Records Field Descriptions This chapter describes the field descriptions of the Call Management Records (CMRs). The chapter contains the following information:, page 8-143

More information

Using NetFlow Sampling to Select the Network Traffic to Track

Using NetFlow Sampling to Select the Network Traffic to Track Using NetFlow Sampling to Select the Network Traffic to Track This module contains information about and instructions for selecting the network traffic to track through the use of NetFlow sampling. The

More information

Configuring AVC to Monitor MACE Metrics

Configuring AVC to Monitor MACE Metrics This feature is designed to analyze and measure network traffic for WAAS Express. Application Visibility and Control (AVC) provides visibility for various applications and the network to central network

More information

Confidence Intervals. Dennis Sun Data 301

Confidence Intervals. Dennis Sun Data 301 Dennis Sun Data 301 Statistical Inference probability Population / Box Sample / Data statistics The goal of statistics is to infer the unknown population from the sample. We ve already seen one mode of

More information

This chapter provides information to configure Cflowd.

This chapter provides information to configure Cflowd. Cflowd In This Chapter This chapter provides information to configure Cflowd. Topics in this chapter include: Cflowd Overview on page 564 Operation on page 565 Cflowd Filter Matching on page 569 Cflowd

More information

Concept: Traffic Flow. Prof. Anja Feldmann, Ph.D. Dr. Steve Uhlig

Concept: Traffic Flow. Prof. Anja Feldmann, Ph.D. Dr. Steve Uhlig Concept: Traffic Flow Prof. Anja Feldmann, Ph.D. Dr. Steve Uhlig 1 Passive measurement capabilities: Packet monitors Available data: All protocol information All content Possible analysis: Application

More information

Internet Engineering Task Force (IETF) Request for Comments: TU Muenchen K. Ishibashi NTT. April 2011

Internet Engineering Task Force (IETF) Request for Comments: TU Muenchen K. Ishibashi NTT. April 2011 Internet Engineering Task Force (IETF) Request for Comments: 6183 Updates: 5470 Category: Informational ISSN: 2070-1721 A. Kobayashi NTT B. Claise Cisco Systems, Inc. G. Muenz TU Muenchen K. Ishibashi

More information

Flow Measurement. For IT, Security and IoT/ICS. Pavel Minařík, Chief Technology Officer EMITEC, Swiss Test and Measurement Day 20 th April 2018

Flow Measurement. For IT, Security and IoT/ICS. Pavel Minařík, Chief Technology Officer EMITEC, Swiss Test and Measurement Day 20 th April 2018 Flow Measurement For IT, Security and IoT/ICS Pavel Minařík, Chief Technology Officer EMITEC, Swiss Test and Measurement Day 20 th April 2018 What is Flow Data? Modern method for network monitoring flow

More information

NetFlow-based bandwidth estimation in IP networks

NetFlow-based bandwidth estimation in IP networks NetFlow-based bandwidth estimation in IP networks Rodrigo Alarcón-Reyes Department of Electrical and Computer Engineering McGill University March 3, 22 Outline. Introduction to NetFlow 2. Definition of

More information

Fine-Grain NBAR for Selective Applications

Fine-Grain NBAR for Selective Applications By default NBAR operates in the fine-grain mode, offering NBAR's full application recognition capabilities. Used when per-packet reporting is required, fine-grain mode offers a troubleshooting advantage.

More information

Monitoring Data CHAPTER

Monitoring Data CHAPTER CHAPTER 4 The Monitor tab provides options for viewing various types of monitored data. There are options for: Overview of Data Collection and Data Sources, page 4-2 Viewing the Monitor Overview Charts,

More information

Monitor Application Health

Monitor Application Health About Application Experience, on page 1 Enable Cisco NetFlow Collection, on page 1 View the Application Experience of a Client Device, on page 2 Monitor the Health of All Applications, on page 3 Monitor

More information

Signature Detection in Sampled Packets

Signature Detection in Sampled Packets Signature Detection in Sampled Packets Gerhard Münz, Nico Weber, Georg Carle Computer Networks and Internet Wilhelm Schickard Institute for Computer Science University of Tuebingen, Germany Abstract Deep

More information

Fine-Grain NBAR for Selective Applications

Fine-Grain NBAR for Selective Applications By default NBAR operates in the fine-grain mode, offering NBAR's full application recognition capabilities. Used when per-packet reporting is required, fine-grain mode offers a troubleshooting advantage.

More information

Configuring NetFlow. Feature History for Configuring NetFlow. Release This feature was introduced.

Configuring NetFlow. Feature History for Configuring NetFlow. Release This feature was introduced. Configuring NetFlow A NetFlow flow is a unidirectional sequence of packets that arrive on a single interface (or subinterface), and have the same values for key fields. NetFlow is useful for the following:

More information

Advanced Stream and Sampling Framework for IPPM

Advanced Stream and Sampling Framework for IPPM Advanced Stream and Sampling Framework for IPPM draft-morton-ippm-2330-update-01 Joachim Fabini and Al Morton March 2013 Status & Motivation Networks have evolved RFC 2330 assumes linear network behavior

More information

Using NetFlow Sampling to Select the Network Traffic to Track

Using NetFlow Sampling to Select the Network Traffic to Track Using NetFlow Sampling to Select the Network Traffic to Track Last Updated: September 17, 2012 This module contains information about and instructions for selecting the network traffic to track through

More information

Network Working Group. Category: Informational Fraunhofer FOKUS J. Quittek M. Stiemerling NEC P. Aitken Cisco Systems, Inc.

Network Working Group. Category: Informational Fraunhofer FOKUS J. Quittek M. Stiemerling NEC P. Aitken Cisco Systems, Inc. Network Working Group Request for Comments: 5153 Category: Informational E. Boschi Hitachi Europe L. Mark Fraunhofer FOKUS J. Quittek M. Stiemerling NEC P. Aitken Cisco Systems, Inc. April 2008 IP Flow

More information

Sampling for Passive Internet Measurement: A Review

Sampling for Passive Internet Measurement: A Review Statistical Science 2004, Vol. 19, No. 3, 472 498 DOI 10.1214/088342304000000206 Institute of Mathematical Statistics, 2004 Sampling for Passive Internet Measurement: A Review Nick Duffield Abstract. Sampling

More information

Best Practices for Determining the Traffic Matrix in IP Networks

Best Practices for Determining the Traffic Matrix in IP Networks Best Practices for Determining the Traffic Matrix in IP Networks Apricot 2005 - Kyoto, Japan Thursday February 24, 2005 Internet Routing and Backbone Operations Session C5-4 Thomas Telkamp, Cariden Technologies,

More information

Configuring NetFlow and NetFlow Data Export

Configuring NetFlow and NetFlow Data Export This module contains information about and instructions for configuring NetFlow to capture and export network traffic data. NetFlow capture and export are performed independently on each internetworking

More information

Covert channel detection using flow-data

Covert channel detection using flow-data Covert channel detection using flow-data Guido Pineda Reyes MSc. Systems and Networking Engineering University of Amsterdam July 3, 2014 Guido Pineda Reyes (UvA) Covert channel detection using flow-data

More information

Monitoring and Analysis

Monitoring and Analysis CHAPTER 3 Cisco Prime Network Analysis Module 5.1 has two types of dashboards: One type is the summary views found under the Monitor menu, and the other type is the over time views found under the Analyze

More information

Computing Optimal Strata Bounds Using Dynamic Programming

Computing Optimal Strata Bounds Using Dynamic Programming Computing Optimal Strata Bounds Using Dynamic Programming Eric Miller Summit Consulting, LLC 7/27/2012 1 / 19 Motivation Sampling can be costly. Sample size is often chosen so that point estimates achieve

More information

AVC Configuration. Unified Policy CLI CHAPTER

AVC Configuration. Unified Policy CLI CHAPTER CHAPTER 3 Revised: February 7, 2013, This chapter addresses AVC configuration and includes the following topics: Unified Policy CLI, page 3-1 Metric Producer Parameters, page 3-2 Reacts, page 3-2 NetFlow/IPFIX

More information

The State of Standardization Efforts to support Data Exchange in the Security Domain

The State of Standardization Efforts to support Data Exchange in the Security Domain The State of Standardization Efforts to support Data Exchange in the Security Domain Roman Danyliw FloCon 2004: Standards Talk Network Group Software Engineering Institute Carnegie Mellon

More information

Power of Slicing in Internet Flow Measurement. Ramana Rao Kompella Cristian Estan

Power of Slicing in Internet Flow Measurement. Ramana Rao Kompella Cristian Estan Power of Slicing in Internet Flow Measurement Ramana Rao Kompella Cristian Estan 1 IP Network Management Network Operator What is happening in my network? How much traffic flows towards a given destination?

More information

Automated Traffic Classification and Application Identification using Machine Learning. Sebastian Zander, Thuy Nguyen, Grenville Armitage

Automated Traffic Classification and Application Identification using Machine Learning. Sebastian Zander, Thuy Nguyen, Grenville Armitage Automated Traffic Classification and Application Identification using Machine Learning Sebastian Zander, Thuy Nguyen, Grenville Armitage {szander,tnguyen,garmitage}@swin.edu.au Centre for Advanced Internet

More information

Introduction to Network Discovery and Identity

Introduction to Network Discovery and Identity The following topics provide an introduction to network discovery and identity policies and data: Host, Application, and User Detection, on page 1 Uses for Host, Application, and User Discovery and Identity

More information

RIPE75 - Network monitoring at scale. Louis Poinsignon

RIPE75 - Network monitoring at scale. Louis Poinsignon RIPE75 - Network monitoring at scale Louis Poinsignon Why monitoring and what to monitor? Why do we monitor? Billing Reducing costs Traffic engineering Where should we peer? Where should we set-up a new

More information

Monitoring Multicast Traffic in Wireless Heterogeneous Networks

Monitoring Multicast Traffic in Wireless Heterogeneous Networks Monitoring Multicast Traffic in Wireless Heterogeneous Networks Filipe Sousa 1 DEEC Faculdade de Engenharia da Universidade do Porto (FEUP) Rua Dr. Roberto Frias, s/n 4200-465 Porto PORTUGAL mpt09014@fe.up.pt

More information

A closer look at network structure:

A closer look at network structure: T1: Introduction 1.1 What is computer network? Examples of computer network The Internet Network structure: edge and core 1.2 Why computer networks 1.3 The way networks work 1.4 Performance metrics: Delay,

More information

USING QUALITY CONTROL CHARTS TO SEGMENT ROAD SURFACE CONDITION DATA

USING QUALITY CONTROL CHARTS TO SEGMENT ROAD SURFACE CONDITION DATA USING QUALITY CONTROL CHARTS TO SEGMENT ROAD SURFACE CONDITION DATA Amin El Gendy Doctoral Candidate Ahmed Shalaby Associate Professor Department of Civil Engineering University of Manitoba Winnipeg, i

More information

SELECTION OF METRICS (CONT) Gaia Maselli

SELECTION OF METRICS (CONT) Gaia Maselli SELECTION OF METRICS (CONT) Gaia Maselli maselli@di.uniroma1.it Computer Network Performance 2 Selecting performance metrics Computer Network Performance 3 Selecting performance metrics speed Individual

More information

1. Estimation equations for strip transect sampling, using notation consistent with that used to

1. Estimation equations for strip transect sampling, using notation consistent with that used to Web-based Supplementary Materials for Line Transect Methods for Plant Surveys by S.T. Buckland, D.L. Borchers, A. Johnston, P.A. Henrys and T.A. Marques Web Appendix A. Introduction In this on-line appendix,

More information

Flexible NetFlow IPFIX Export Format

Flexible NetFlow IPFIX Export Format The feature enables sending export packets using the IPFIX export protocol. The export of extracted fields from NBAR is only supported over IPFIX. Finding Feature Information, page 1 Information About,

More information

Real-Time and Resilient Intrusion Detection: A Flow-Based Approach

Real-Time and Resilient Intrusion Detection: A Flow-Based Approach Real-Time and Resilient Intrusion Detection: A Flow-Based Approach Rick Hofstede, Aiko Pras To cite this version: Rick Hofstede, Aiko Pras. Real-Time and Resilient Intrusion Detection: A Flow-Based Approach.

More information

Monitoring Data CHAPTER

Monitoring Data CHAPTER CHAPTER 4 The Monitor tab provides options to view various types of monitored data. There are options for: Viewing the Monitor Overview Charts, page 4-9 Viewing Application Data, page 4-12 Viewing Voice

More information

Using NetFlow Filtering or Sampling to Select the Network Traffic to Track

Using NetFlow Filtering or Sampling to Select the Network Traffic to Track Using NetFlow Filtering or Sampling to Select the Network Traffic to Track First Published: June 19, 2006 Last Updated: December 17, 2010 This module contains information about and instructions for selecting

More information

From NetFlow to IPFIX the evolution of IP flow information export

From NetFlow to IPFIX the evolution of IP flow information export From NetFlow to IPFIX the evolution of IP flow information export Brian Trammell - CERT/NetSA - Pittsburgh, PA, US Elisa Boschi - Hitachi Europe - Zurich, CH NANOG 41 - Albuquerque, NM, US - October 15,

More information

Basic Concepts in Intrusion Detection

Basic Concepts in Intrusion Detection Technology Technical Information Services Security Engineering Roma, L Università Roma Tor Vergata, 23 Aprile 2007 Basic Concepts in Intrusion Detection JOVAN GOLIĆ Outline 2 Introduction Classification

More information

Cisco IOS Flexible NetFlow Command Reference

Cisco IOS Flexible NetFlow Command Reference Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION

More information

Hardware-Accelerated Flexible Flow Measurement

Hardware-Accelerated Flexible Flow Measurement Hardware-Accelerated Flexible Flow Measurement Pavel Čeleda celeda@liberouter.org Martin Žádník zadnik@liberouter.org Lukáš Solanka solanka@liberouter.org Part I Introduction and Related Work Čeleda, Žádník,

More information

How can we gain the insights and control we need to optimize the performance of applications running on our network?

How can we gain the insights and control we need to optimize the performance of applications running on our network? SOLUTION BRIEF CA Network Flow Analysis and Cisco Application Visibility and Control How can we gain the insights and control we need to optimize the performance of applications running on our network?

More information

Introduction to Routers and LAN Switches

Introduction to Routers and LAN Switches Introduction to Routers and LAN Switches Session 3048_05_2001_c1 2001, Cisco Systems, Inc. All rights reserved. 3 Prerequisites OSI Model Networking Fundamentals 3048_05_2001_c1 2001, Cisco Systems, Inc.

More information

Introduction to Network Discovery and Identity

Introduction to Network Discovery and Identity The following topics provide an introduction to network discovery and identity policies and data: Host, Application, and User Detection, page 1 Uses for Host, Application, and User Discovery and Identity

More information

UnivMon: Software-defined Monitoring with Universal Sketch

UnivMon: Software-defined Monitoring with Universal Sketch UnivMon: Software-defined Monitoring with Universal Sketch Zaoxing (Alan) Liu Joint work with Antonis Manousis (CMU), Greg Vorsanger(JHU), Vyas Sekar (CMU), and Vladimir Braverman(JHU) Network Management:

More information

H3C SR6600/SR6600-X Routers

H3C SR6600/SR6600-X Routers H3C SR6600/SR6600-X Routers Network Management and Monitoring Command Reference Hangzhou H3C Technologies Co., Ltd. http://www.h3c.com Software version: SR6600X-CMW520-R3103 SR6602-CMW520-R3103 SR6602X_MCP-CMW520-R3103

More information

Internet Engineering Task Force (IETF) Request for Comments: November 2012

Internet Engineering Task Force (IETF) Request for Comments: November 2012 Internet Engineering Task Force (IETF) Request for Comments: 6759 Category: Informational ISSN: 2070-1721 B. Claise P. Aitken N. Ben-Dvora Cisco Systems, Inc. November 2012 Cisco Systems Export of Application

More information

Internet Engineering Task Force (IETF) B. Claise Cisco Systems, Inc. G. Muenz Technische Universitaet Muenchen April 2010

Internet Engineering Task Force (IETF) B. Claise Cisco Systems, Inc. G. Muenz Technische Universitaet Muenchen April 2010 Internet Engineering Task Force (IETF) Request for Comments: 5815 Category: Standards Track ISSN: 2070-1721 T. Dietz, Ed. NEC Europe, Ltd. A. Kobayashi NTT PF Labs. B. Claise Cisco Systems, Inc. G. Muenz

More information

NetFlow Monitoring. NetFlow Monitoring

NetFlow Monitoring. NetFlow Monitoring , page 1 NetFlow Limitations, page 2 Creating a Flow Record Definition, page 3 Viewing Flow Record Definitions, page 4 Defining the Exporter Profile, page 4 Creating a Flow Collector, page 5 Creating a

More information

Consider these restrictions when configuring NetFlow in Cisco IOS XR software: Do not use the management interface to export the NetFlow packets.

Consider these restrictions when configuring NetFlow in Cisco IOS XR software: Do not use the management interface to export the NetFlow packets. A NetFlow flow is a unidirectional sequence of packets that arrive on a single interface, and have the same values for key fields. NetFlow is useful for the following: Accounting/Billing NetFlow data provides

More information

Deployment of Sampling Methods for SLA Validation with Non-Intrusive Measurements

Deployment of Sampling Methods for SLA Validation with Non-Intrusive Measurements Deployment of ampling ethods for LA Validation with Non-Intrusive easurements Tanja Zseby FOKU - Fraunhofer Institute for Open ommunication ystems Kaiserin-Augusta-Allee 3, 589 Berlin, Germany zseby@fokus.fhg.de

More information

FloCon 2006 Proceedings

FloCon 2006 Proceedings FloCon 2006 Proceedings January 2006 CERT Program http://www.sei.cmu.edu Report Documentation Page Form Approved OMB No. 0704-0188 Public reporting burden for the collection of information is estimated

More information

Performance Evaluation of WiFiRe using OPNET

Performance Evaluation of WiFiRe using OPNET Performance Evaluation of WiFiRe using OPNET Under the guidance of: Prof. Sridhar Iyer and Prof. Varsha Apte Dept. of CSE (KReSIT) July 16, 2007 Goal Goal Building. Finding minimum slot length to support

More information

SD-WAN Deployment Guide (CVD)

SD-WAN Deployment Guide (CVD) SD-WAN Deployment Guide (CVD) All Cisco Meraki security appliances are equipped with SD-WAN capabilities that enable administrators to maximize network resiliency and bandwidth efficiency. This guide introduces

More information

Trajectory Sampling: White Paper Draft

Trajectory Sampling: White Paper Draft Trajectory Sampling: White Paper Draft Nick Duffield Matthias Grossglauser April 10, 2003 1 Executive Summary Trajectory Sampling (TS) is a novel method to measure network traffic in potentially large

More information

Configuring Cisco IOS IP SLA Operations

Configuring Cisco IOS IP SLA Operations CHAPTER 58 This chapter describes how to use Cisco IOS IP Service Level Agreements (SLA) on the switch. Cisco IP SLA is a part of Cisco IOS software that allows Cisco customers to analyze IP service levels

More information

Zone-Based Firewall Logging Export Using NetFlow

Zone-Based Firewall Logging Export Using NetFlow Zone-Based Firewall Logging Export Using NetFlow Zone-based firewalls support the logging of messages to an external collector using NetFlow Version 9 export format. NetFlow Version 9 export format uses

More information

Configuring Cisco IOS IP SLAs Operations

Configuring Cisco IOS IP SLAs Operations CHAPTER 50 This chapter describes how to use Cisco IOS IP Service Level Agreements (SLAs) on the switch. Cisco IP SLAs is a part of Cisco IOS software that allows Cisco customers to analyze IP service

More information

NetFlow Multiple Export Destinations

NetFlow Multiple Export Destinations Feature History Release 12.0(19)S 12.0(19)ST 12.2(2)T 12.2(14)S Modification This feature was introduced on the Cisco 12000 Internet router. This feature was integrated into Cisco IOS Release 12.0(19)ST.

More information

Information, Gravity, and Traffic Matrices

Information, Gravity, and Traffic Matrices Information, Gravity, and Traffic Matrices Yin Zhang, Matthew Roughan, Albert Greenberg, Nick Duffield, David Donoho 1 Problem Have link traffic measurements Want to know demands from source to destination

More information

MAD 12 Monitoring the Dynamics of Network Traffic by Recursive Multi-dimensional Aggregation. Midori Kato, Kenjiro Cho, Michio Honda, Hideyuki Tokuda

MAD 12 Monitoring the Dynamics of Network Traffic by Recursive Multi-dimensional Aggregation. Midori Kato, Kenjiro Cho, Michio Honda, Hideyuki Tokuda MAD 12 Monitoring the Dynamics of Network Traffic by Recursive Multi-dimensional Aggregation Midori Kato, Kenjiro Cho, Michio Honda, Hideyuki Tokuda 1 Background Traffic monitoring is important to detect

More information

Homework 1 50 points. Quantitative Comparison of Packet Switching and Circuit Switching 20 points Consider the two scenarios below:

Homework 1 50 points. Quantitative Comparison of Packet Switching and Circuit Switching 20 points Consider the two scenarios below: Homework 1 50 points Quantitative Comparison of Packet Switching and Circuit Switching 20 points Consider the two scenarios below: A circuit-switching scenario in which Ncs users, each requiring a bandwidth

More information

A packet based method for passive performance monitoring

A packet based method for passive performance monitoring A packet based method for passive performance monitoring draft-tempia-ippm-p3m-03 Buenos Aires, Apr 2015, IETF 95 Alessandro Capello Mauro Cociglio Giuseppe Fioccola Marking Method Recap Packet Loss Measurement:

More information

HyperTransport. Dennis Vega Ryan Rawlins

HyperTransport. Dennis Vega Ryan Rawlins HyperTransport Dennis Vega Ryan Rawlins What is HyperTransport (HT)? A point to point interconnect technology that links processors to other processors, coprocessors, I/O controllers, and peripheral controllers.

More information

Analyzing Cacheable Traffic in ISP Access Networks for Micro CDN applications via Content-Centric Networking

Analyzing Cacheable Traffic in ISP Access Networks for Micro CDN applications via Content-Centric Networking Analyzing Cacheable Traffic in ISP Access Networks for Micro CDN applications via Content-Centric Networking Claudio Imbrenda Luca Muscariello Orange Labs Dario Rossi Telecom ParisTech Outline Motivation

More information

GUARANTEED END-TO-END LATENCY THROUGH ETHERNET

GUARANTEED END-TO-END LATENCY THROUGH ETHERNET GUARANTEED END-TO-END LATENCY THROUGH ETHERNET Øyvind Holmeide, OnTime Networks AS, Oslo, Norway oeyvind@ontimenet.com Markus Schmitz, OnTime Networks LLC, Texas, USA markus@ontimenet.com Abstract: Latency

More information

Cisco Call Management Record Field

Cisco Call Management Record Field Cisco Call Management Record Field s This chapter describes the field descriptions of the Call Management Records (CMRs). CMR Field s, page 1 CMR Field s The following table contains the fields, range

More information

CPSC 441 Tutorial-1. Department of Computer Science University of Calgary

CPSC 441 Tutorial-1. Department of Computer Science University of Calgary CPSC 441 Tutorial-1 Department of Computer Science University of Calgary Question-1 A packet switch receives a packet and determines the outbound link to which the packet should be forwarded. When the

More information

Technology Overview. Overview CHAPTER

Technology Overview. Overview CHAPTER CHAPTER 2 Revised: July 29, 2013, This overview of AVC technology includes the following topics: Overview, page 2-1 AVC Features and Capabilities, page 2-2 AVC Architecture, page 2-4 Interoperability of

More information

Heavy-Hitter Detection Entirely in the Data Plane

Heavy-Hitter Detection Entirely in the Data Plane Heavy-Hitter Detection Entirely in the Data Plane VIBHAALAKSHMI SIVARAMAN SRINIVAS NARAYANA, ORI ROTTENSTREICH, MUTHU MUTHUKRSISHNAN, JENNIFER REXFORD 1 Heavy Hitter Flows Flows above a certain threshold

More information

Towards Bandwidth Estimation Using Flow-Level Measurements

Towards Bandwidth Estimation Using Flow-Level Measurements Towards Bandwidth Estimation Using Flow-Level Measurements Ricardo O. Schmidt, Anna Sperotto, Ramin Sadre, Aiko Pras To cite this version: Ricardo O. Schmidt, Anna Sperotto, Ramin Sadre, Aiko Pras. Towards

More information

Configuring sflow. About sflow. sflow Agent

Configuring sflow. About sflow. sflow Agent About sflow This chapter describes how to configure sflow on Cisco NX-OS devices. This chapter includes the following sections: About sflow, on page 1 Licensing Requirements for sflow, on page 2 Prerequisites

More information

Modular Quality of Service Overview on Cisco IOS XR Software

Modular Quality of Service Overview on Cisco IOS XR Software Modular Quality of Service Overview on Cisco IOS XR Software Quality of Service (QoS) is the technique of prioritizing traffic flows and providing preferential forwarding for higher-priority packets. The

More information

Monitoring and diagnostics of data infrastructure problems in power engineering. Jaroslav Stusak, Sales Director CEE, Flowmon Networks

Monitoring and diagnostics of data infrastructure problems in power engineering. Jaroslav Stusak, Sales Director CEE, Flowmon Networks Monitoring and diagnostics of data infrastructure problems in power engineering Jaroslav Stusak, Sales Director CEE, Flowmon Networks 35,000 kilometers of electric power, which feeds around 740,000 clients...

More information

Lecture 2: Streaming Algorithms for Counting Distinct Elements

Lecture 2: Streaming Algorithms for Counting Distinct Elements Lecture 2: Streaming Algorithms for Counting Distinct Elements 20th August, 2008 Streaming Algorithms Streaming Algorithms Streaming algorithms have the following properties: 1 items in the stream are

More information

Configuring IP SLA UDP Jitter Operations

Configuring IP SLA UDP Jitter Operations This chapter describes how to configure an IP Service Level Agreements (SLAs) UDP jitter operation to analyze round-trip delay, one-way delay, one-way jitter, one-way packet loss, and connectivity in networks

More information

A Study of Impacts of Flow Timeouts on Link Provisioning

A Study of Impacts of Flow Timeouts on Link Provisioning A Study of Impacts of Flow Timeouts on Link Provisioning Jeroen Fokkema University of Twente P.O. Box 217, 7500AE Enschede The Netherlands j.fokkema@student.utwente.nl ABSTRACT Link provisioning is used

More information

A Framework for Efficient Class-based Sampling

A Framework for Efficient Class-based Sampling A Framework for Efficient Class-based Sampling Mohit Saxena and Ramana Rao Kompella Department of Computer Science Purdue University West Lafayette, IN, 47907 Email: {msaxena,kompella}@cs.purdue.edu Abstract

More information

fair-queue aggregate-limit

fair-queue aggregate-limit Quality of Service Commands aggregate-limit aggregate-limit To set the maximum number of packets in all queues combined for VIP-distributed weighted fair queueing (DWFQ), use the aggregate-limit interface

More information

(ICMP), RFC

(ICMP), RFC Internet et Control o Message Protocol (ICMP), RFC 792 http://icourse.cuc.edu.cn/networkprogramming/ linwei@cuc.edu.cn Nov. 2009 Overview The IP (Internet Protocol) relies on several other protocols to

More information

Promoting the Use of End-to-End Congestion Control in the Internet

Promoting the Use of End-to-End Congestion Control in the Internet Promoting the Use of End-to-End Congestion Control in the Internet Sally Floyd and Kevin Fall IEEE/ACM Transactions on Networking May 1999 ACN: TCP Friendly 1 Outline The problem of Unresponsive Flows

More information

Flexible NetFlow - Top N Talkers Support

Flexible NetFlow - Top N Talkers Support This document contains information about and instructions for using the Flexible NetFlow - Top N Talkers Support feature. The feature helps you analyze the large amount of data that Flexible NetFlow captures

More information