Distributed architecture for real-time traffic analysis

  • Authors:
  • Cristian Morariu;Burkhard Stiller

  • Affiliations:
  • Department of Informatics, University of Zürich, Department of Informatics, University of Zürich;Department of Informatics, University of Zürich, Department of Informatics, University of Zürich

  • Venue:
  • AIMS'10 Proceedings of the Mechanisms for autonomous management of networks and services, and 4th international conference on Autonomous infrastructure, management and security
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traditional real-time IP traffic analysis applied on todays' high-speed network links suffers from the lack of scalability. Although sampling proves to be a promising approach, there are application scenarios foreseen, in which decisions cannot be based on sampled data, e.g., for usage-based charging or intrusion detection systems. Moreover, traditional traffic analysis mechanisms do not map the traffic observed in the network to a particular user, but rather to a particular end-node, which may have been shared by several users. Thus, DARTA (Distributed Architecture for Real-time Traffic Analysis) develops a model for distributed IP traffic analysis and introduces new mechanisms for three different aspects in IP traffic monitoring: (a) a framework enabling the development of distributed traffic analysis applications, (b) a distributed packet capture mechanism, (c) an user-based IP traffic accounting for mapping IP traffic to individual users.