DocumentCode
1719460
Title
Flexible Flow Aggregation for Adaptive Network Monitoring
Author
Dressler, Falko ; Munz, Gerhard
Author_Institution
Dept. of Comput. Sci. 7, Erlangen Univ.
fYear
2006
Firstpage
702
Lastpage
709
Abstract
Network monitoring is a major building block for many domains in communication networks. Besides typical accounting mechanisms and the emerging area of charging in next generation networks, especially network security solutions rely on efficient and optimized monitoring. Network monitoring in high-speed networks is usually based on flow accounting and aggregation techniques represent a necessary enhancement in order to cope with increasing amounts of monitoring data that accrue with the ever-growing network capacities. In this paper, we propose a flexible flow aggregation mechanism that can be directly employed on a monitoring probe to reduce the memory and processing demands. Alternatively, it can work as a concentrator that collects flow data from multiple monitoring probes, combines and aggregates them and forwards the results to an analyzer. We verified and evaluated the aggregation mechanism by integrating it into our monitoring probe Vermont. Our approach opens new prospects for high-speed network monitoring and allows coping with special situations that cannot be treated satisfyingly by traditional flow accounting, such as distributed denial-of-service attacks causing very high numbers of flows. Aggregated flow data are an easy-to-handle form of packet information especially for anomaly detection and accounting issues
Keywords
computer network management; telecommunication congestion control; telecommunication security; adaptive network monitoring probe; aggregated flow data; communication network security; flexible flow aggregation mechanism; flow accounting; multiple monitoring probe; packet information; processing demand; Adaptive systems; Computer crime; Computer networks; Computer science; Computerized monitoring; IP networks; Next generation networking; Probes; Protocols; Sampling methods;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks, Proceedings 2006 31st IEEE Conference on
Conference_Location
Tampa, FL
ISSN
0742-1303
Print_ISBN
1-4244-0418-5
Electronic_ISBN
0742-1303
Type
conf
DOI
10.1109/LCN.2006.322180
Filename
4116641
Link To Document