Next Generation Application-Aware Flow Monitoring
Petr Velan
velan@ics.muni.cz
} w- Æ
- !
- .
AIMS 2014
July 3, 2014 Brno
Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 1 / 10
Next Generation Application-Aware Flow Monitoring Petr Velan } , - - PowerPoint PPT Presentation
Next Generation Application-Aware Flow Monitoring Petr Velan } , ! " # $ % & ' ( ) + - A| / 0 1 2 3 4 5 < y . w
velan@ics.muni.cz
} wPetr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 1 / 10
Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 2 / 10
Packets Flow Cache Flow Processing L2-L4 Header Processing Application Processing IPFIX Message Transport Protocol Flow records Metering Process Exporting Process
Flow start Duration Proto Src IP Addr:Port Dst IP Addr:Port Flags Packets Bytes 09:41:21.763 0.101 TCP 172.16.96.48:15094 -> 209.85.135.147:80 .AP.SF 4 715 09:41:21.893 0.031 TCP 209.85.135.147:80 -> 172.16.96.48:15094 .AP.SF 4 1594
HTTP RT HTTP Host HTTP Path HTTP Code HTTP Type GET www.seznam.cz /favicons/019/194-DBrJCJ.png
image/x-icon Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 3 / 10
[1] Petr Velan, Tomáš Jirsík and Pavel ˇ
Lecture Notes in Computer Science, Vol. 8115, pages 136-147, Chemnitz, Germany, 2013. Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 4 / 10
1 2 3 4 5 6 11 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% 100% Packets/s (x 106) no HTTP
strcmp
flex pcre
Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 5 / 10
Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 6 / 10
[1] Pavel ˇ Celeda, Petr Velan, Martin Rábek, Rick Hofstede and Aiko Pras. Large-Scale Geolocation for NetFlow. In IFIP/IEEE International Symposium on Integrated Network Management (IM 2013), pages 1015-1020, Ghent, Belgium, 2013. [2] Martin Elich, Petr Velan, Tomáš Jirsík and Pavel ˇ
Traffic Analysis. In 38th Annual IEEE Conference on Local Computer Networks (LCN 2013), pages 1046-1052, Sydney, Australia, 2013. Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 7 / 10
Open wikipedia.org
DNS server IP wikipedia.org 208.80.154.224 GET wikipedia.org Response HTML GET bits.wikimedia.org Response style.css G E T u p l
d . w i k i m e d i a .
g R e s p
s e l
p n g 91.198.174.202 91.198.174.208 208.80.154.224 Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 8 / 10
Spring '14 Autumn '15 Spring '16 Autumn '14 Spring '15 R.Q. 1 R.Q. 3 R.Q. 2 R.Q. 4
Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 9 / 10
Petr Velan (AIMS 2014) Next Generation Flow Monitoring July 3, 2014, Brno 10 / 10