Characteristics of wide-area TCP/IP conversations
SIGCOMM '91 Proceedings of the conference on Communications architecture & protocols
On the self-similar nature of Ethernet traffic (extended version)
IEEE/ACM Transactions on Networking (TON)
Empirically derived analytic models of wide-area TCP connections
IEEE/ACM Transactions on Networking (TON)
Wide area traffic: the failure of Poisson modeling
IEEE/ACM Transactions on Networking (TON)
Automated packet trace analysis of TCP implementations
SIGCOMM '97 Proceedings of the ACM SIGCOMM '97 conference on Applications, technologies, architectures, and protocols for computer communication
End-to-end routing behavior in the Internet
IEEE/ACM Transactions on Networking (TON)
Self-similarity in World Wide Web traffic: evidence and possible causes
IEEE/ACM Transactions on Networking (TON)
Summary cache: a scalable wide-area Web cache sharing protocol
Proceedings of the ACM SIGCOMM '98 conference on Applications, technologies, architectures, and protocols for computer communication
Self-similarity and heavy tails: structural modeling of network traffic
A practical guide to heavy tails
Bro: a system for detecting network intruders in real-time
Computer Networks: The International Journal of Computer and Telecommunications Networking
IP packet generation: statistical models for TCP start times based on connection-rate superposition
Proceedings of the 2000 ACM SIGMETRICS international conference on Measurement and modeling of computer systems
What TCP/IP protocol headers can tell us about the web
Proceedings of the 2001 ACM SIGMETRICS international conference on Measurement and modeling of computer systems
Proceedings of the 2001 conference on Applications, technologies, architectures, and protocols for computer communications
Monitoring very high speed links
IMW '01 Proceedings of the 1st ACM SIGCOMM Workshop on Internet Measurement
Passive estimation of TCP round-trip times
ACM SIGCOMM Computer Communication Review
An Empirical Model of HTTP Network Traffic
INFOCOM '97 Proceedings of the INFOCOM '97. Sixteenth Annual Joint Conference of the IEEE Computer and Communications Societies. Driving the Information Revolution
Measurement and classification of out-of-sequence packets in a tier-1 IP backbone
IEEE/ACM Transactions on Networking (TON)
Sting: a TCP-based network measurement tool
USITS'99 Proceedings of the 2nd conference on USENIX Symposium on Internet Technologies and Systems - Volume 2
The measured access characteristics of world-wide-web client proxy caches
USITS'97 Proceedings of the USENIX Symposium on Internet Technologies and Systems on USENIX Symposium on Internet Technologies and Systems
Effective traffic measurement using ntop
IEEE Communications Magazine
Bottleneck detection in UMTS via TCP passive monitoring: a real case
CoNEXT '05 Proceedings of the 2005 ACM conference on Emerging network experiment and technology
KISS: Stochastic Packet Inspection
TMA '09 Proceedings of the First International Workshop on Traffic Monitoring and Analysis
Two schemes to reduce latency in short lived TCP flows
IEEE Communications Letters
Netcluster: a clustering-based framework for internet tomography
ICC'09 Proceedings of the 2009 IEEE international conference on Communications
Experiences of VoIP traffic monitoring in a commercial ISP
International Journal of Network Management
KISS: stochastic packet inspection classifier for UDP traffic
IEEE/ACM Transactions on Networking (TON)
Packet-Mode priority scheduling for terabit core routers
ISPA'04 Proceedings of the Second international conference on Parallel and Distributed Processing and Applications
Topological design of survivable IP networks using metaheuristic approaches
QoS-IP'05 Proceedings of the Third international conference on Quality of Service in Multiservice IP Networks
Secure and efficient validation of data traffic flows in fixed and mobile networks
Proceedings of the 7th ACM workshop on Performance monitoring and measurement of heterogeneous wireless and wired networks
Assessing the quality of packet-level traces collected on internet backbone links
NordSec'12 Proceedings of the 17th Nordic conference on Secure IT Systems
Hi-index | 0.00 |
Field measurements have always been the starting point for network design and planning; however, their statistical analysis beyond simple traffic volume estimation is not so common. In this paper we present and discuss Tstat, a tool for the collection and statistical analysis of TCP/IP traffic, which, in addition to recognized performance figures, infers TCP connection status from traces. Besides briefly discussing its rationale and use, we present part of the performance figures that can be obtained, and we highlight the insight that such figures can give on TCP/IP protocols and the Internet, thereby supporting the usefulness of a widespread use of Tstat or similar tools. Analyzing Internet traffic is difficult because a large amount of performance figures can be devised in TCP/IP networks, but also because many performance figures can be derived only if both directions of bidirectional traffic are jointly considered. Tstat automatically correlates incoming and outgoing packets. Sophisticated statistics, obtained through data correlation between incoming and outgoing traffic, give reliable estimates of the network performance also from the user perspective. Tstat computes over 80 different performance statistics at both the IP and TCP layers, allowing a good insight in the network performance. To support the latter statement, we discuss several of these figures computed on traffic measurements performed for a time period equivalent to more than three months spread during the years 2000-2003 on the access link of Politecnico di Torino.