• DocumentCode
    2071271
  • Title

    Blink: Large-scale P2P network monitoring and visualization system using VM introspection

  • Author

    Ando, Ruo ; Kadobayashi, Youki ; Shinoda, Yoichi

  • Author_Institution
    Nat. Inst. of Inf. & Commun. Technol., Koganei, Japan
  • fYear
    2010
  • fDate
    16-18 Aug. 2010
  • Firstpage
    351
  • Lastpage
    358
  • Abstract
    P2P network is now widely pervasive and increase usability of Internet. However, with the difficulty of tracing flow of P2P traffic, security incident of P2P network has become now serious problem. In this paper we propose Blink, Large-scale P2P network monitoring and visualization system enhanced by VM introspection. We discuss a monitoring and visualizing P2P traffic using the combination of virtualized probe and analyzer on VMM side. In proposed system, probe and monitor are running on guest OS, which is connected to the analyzer and visualizer module on VMM and host OS. Traffic log is transferred to host OS using VM introspection and is analyzed and visualized. Proposed system makes it possible to enhance the analysis and visualization functionality with the least impact of guest OS. Also, proposed system supports large scale traffic log analysis with large amount of disks necessary using storage of host OS. In proposed system we have implemented monitors for two kinds of P2P software: BitTorrent and Winny. Also we have implemented visualization module using Google Earth by translating traffic log file to KML (Keyhole Markup Language). We show system output of visualizing of traffic log of Winny and BitTorrent. We can conclude that proposed system of double-layer architecture can enhance the functionality of analyzing, storing and visualizing P2P traffic logs.
  • Keywords
    data visualisation; peer-to-peer computing; system monitoring; telecommunication traffic; virtual machines; BitTorrent; Blink; Google Earth; P2P traffic; Winny; double layer architecture; keyhole markup language; large scale P2P network monitoring; large scale traffic log analysis; network visualization system; virtual machine introspection; virtualized analyzer; virtualized probe; Monitoring; Probes; Topology; Visualization; KML; P2P network; VM introspection; active monitor; passive monitor;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networked Computing and Advanced Information Management (NCM), 2010 Sixth International Conference on
  • Conference_Location
    Seoul
  • Print_ISBN
    978-1-4244-7671-8
  • Electronic_ISBN
    978-89-88678-26-8
  • Type

    conf

  • Filename
    5572049