• DocumentCode
    1719460
  • Title

    Flexible Flow Aggregation for Adaptive Network Monitoring

  • Author

    Dressler, Falko ; Munz, Gerhard

  • Author_Institution
    Dept. of Comput. Sci. 7, Erlangen Univ.
  • fYear
    2006
  • Firstpage
    702
  • Lastpage
    709
  • Abstract
    Network monitoring is a major building block for many domains in communication networks. Besides typical accounting mechanisms and the emerging area of charging in next generation networks, especially network security solutions rely on efficient and optimized monitoring. Network monitoring in high-speed networks is usually based on flow accounting and aggregation techniques represent a necessary enhancement in order to cope with increasing amounts of monitoring data that accrue with the ever-growing network capacities. In this paper, we propose a flexible flow aggregation mechanism that can be directly employed on a monitoring probe to reduce the memory and processing demands. Alternatively, it can work as a concentrator that collects flow data from multiple monitoring probes, combines and aggregates them and forwards the results to an analyzer. We verified and evaluated the aggregation mechanism by integrating it into our monitoring probe Vermont. Our approach opens new prospects for high-speed network monitoring and allows coping with special situations that cannot be treated satisfyingly by traditional flow accounting, such as distributed denial-of-service attacks causing very high numbers of flows. Aggregated flow data are an easy-to-handle form of packet information especially for anomaly detection and accounting issues
  • Keywords
    computer network management; telecommunication congestion control; telecommunication security; adaptive network monitoring probe; aggregated flow data; communication network security; flexible flow aggregation mechanism; flow accounting; multiple monitoring probe; packet information; processing demand; Adaptive systems; Computer crime; Computer networks; Computer science; Computerized monitoring; IP networks; Next generation networking; Probes; Protocols; Sampling methods;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks, Proceedings 2006 31st IEEE Conference on
  • Conference_Location
    Tampa, FL
  • ISSN
    0742-1303
  • Print_ISBN
    1-4244-0418-5
  • Electronic_ISBN
    0742-1303
  • Type

    conf

  • DOI
    10.1109/LCN.2006.322180
  • Filename
    4116641