Experiences of Internet Traffic Monitoring with Tstat

被引:116
作者
Finamore, Alessandro [1 ]
Mellia, Marco [2 ]
Meo, Michela
Munafo, Maurizio M. [3 ]
Rossi, Dario
机构
[1] Politecn Torino, Telecommun Network Grp, Turin, Italy
[2] Politecn Torino, Dept Elect Engn, Turin, Italy
[3] Politecn Torino, Dept Elect, Turin, Italy
来源
IEEE NETWORK | 2011年 / 25卷 / 03期
关键词
D O I
10.1109/MNET.2011.5772055
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Since the early days of the Internet, network traffic monitoring has always played a strategic role in understanding and characterizing users' activities. In this article, we present our experience in engineering and deploying Tstat, an open source passive monitoring tool that has been developed in the past 10 years. Started as a scalable tool to continuously monitor packets that flow on a link, Tstat has evolved into a complex application that gives network researchers and operators the possibility to derive extended and complex measurements thanks to advanced traffic classifiers. After discussing Tstat capabilities and internal design, we present some examples of measurements collected deploying Tstat at the edge of several ISP networks in past years. While other works report a continuous decline of P2P traffic with streaming and file hosting services rapidly increasing in popularity, the results presented in this article picture a different scenario. First, P2P decline has stopped, and in the last months of 2010 there was a counter tendency to increase P2P traffic over UDP, so the common belief that UDP traffic is negligible is not true anymore. Furthermore, streaming and file hosting applications have either stabilized or are experiencing decreasing traffic shares. We then discuss the scalability issues software-based tools have to cope with when deployed in real networks, showing the importance of properly identifying bottlenecks.
引用
收藏
页码:8 / 14
页数:7
相关论文
共 11 条
[1]  
[Anonymous], LOW EXTRA D IN PRESS
[2]  
Cottrell L., 2009, Network monitoring tools
[3]  
FINAMORE A, 2010, 8 INT C WIR WIR INT
[4]   KISS: Stochastic Packet Inspection Classifier for UDP Traffic [J].
Finamore, Alessandro ;
Mellia, Marco ;
Meo, Michela ;
Rossi, Dario .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2010, 18 (05) :1505-1515
[5]  
KIM H, 2008, ACM CONEXT 2008 MADR, P12
[6]  
LABOVITZ C, 2010, ACM SIGCOMM NEW DELH
[7]  
Mellia M, 2005, COMPUT NETW, V47, P1, DOI 10.1016/j.comnet.2004.06.026
[8]   A Survey of Techniques for Internet Traffic Classification using Machine Learning [J].
Nguyen, Thuy T. T. ;
Armitage, Grenville .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2008, 10 (04) :56-76
[9]  
PIETRZYK M, 2009, ACM INT MEAS C CHIC
[10]  
ROSSI D, 2006, IEEE INT C COMM ICC