An Architecture for Distributed Real-Time Passive Network Measurement

  • Authors:
  • Tilman Wolf;Ramaswamy Ramaswamy;Siddhartha Bunga;Ning Yang

  • Affiliations:
  • University of Massachusetts Amherst, USA;University of Massachusetts Amherst, USA;University of Massachusetts Amherst, USA;University of Massachusetts Amherst, USA

  • Venue:
  • MASCOTS '06 Proceedings of the 14th IEEE International Symposium on Modeling, Analysis, and Simulation
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present an architecture for a Distributed Online Measurement Environment (DOME) which is a passive measurement system that correlates network information between several measurement nodes placed at different locations in the network to offer a large scale view of network operation. The system is capable of capturing packet traces and pre-processing them on the measurement node itself. Real-time queries are implemented by breaking them down into standard statistics that are updated during run-time. We present details of a prototype implementation of our architecture on an Intel IXP2400 network processor. The prototype is deployed on the main Internet access link of the University of Massachusetts and measurement results are validated against those obtained from an Endace DAG card. Performance of the prototype is compared to that of a conventional post processing system for an application to detect network anomalies.