Live traffic monitoring with tstat: capabilities and experiences

  • Authors:
  • A. Finamore;M. Mellia;M. Meo;M. M. Munafò;D. Rossi

  • Affiliations:
  • Politecnico di Torino;Politecnico di Torino;Politecnico di Torino;Politecnico di Torino;TELECOM ParisTech

  • Venue:
  • WWIC'10 Proceedings of the 8th international conference on Wired/Wireless Internet Communications
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Network monitoring has always played a key role in understanding telecommunication networks since the pioneering time of the Internet. Today, monitoring traffic has become a key element to characterize network usage and users’ activities, to understand how complex applications work, to identify anomalous or malicious behaviors, etc. In this paper we present our experience in engineering and deploying Tstat, a passive monitoring tool that has been developed in the past ten years. Started as a scalable tool to continuously monitor packets that flow on a link, Tstat has evolved into a complex application that gives to network researchers and operators the possibility to derive extended and complex measurements. Tstat offers the capability to track traffic flows, it integrates advanced behavioral classifiers that identify the application that has generated a flow, and automatically derives performance indexes that allow to easily characterize both network usage and users’ activity. After describing Tstat capabilities and internal design, in this paper we present some examples of measurements collected deploying Tstat at the edge of our campus network for the past years.