A Distributed Architecture for IP Traffic Analysis

  • Authors:
  • Cristian Morariu;Burkhard Stiller

  • Affiliations:
  • Department of Informatics, University of Zürich CH-8050, Zürich, Switzerland;Department of Informatics, University of Zürich CH-8050, Zürich, Switzerland

  • Venue:
  • AIMS '07 Proceedings of the 1st international conference on Autonomous Infrastructure, Management and Security: Inter-Domain Management
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Current high-speed links become a challenge to traditional real-time analysis of IP traffic. Major research was done in finding sampling methods for IP packets and IP flows in order to reduce the amount of data that needs to be processed while keeping a high level of result accuracy. Although sampling proves to be a promising approach, there may be application sce-narios foreseen, in which decisions may not be based on sampled data, e.g.,usage based charging or intrusion detection systems. This paper proposes a distributed architecture for collecting, analysing and storing of IP traffic data. This approach aims to provide a high level of automation, self-configuration, and self-healing so that new nodes may be easily added or removed to/from the analysis network. The proposed solution makes use of unused processing power existing in the network (such as customer's PCs of an ISP) to achieve real-time analysis of IP traffic for high-speed network links.