Passive Measurement in CSTNET



Similar documents
Network Monitoring and Traffic CSTNET, CNIC

Viete, čo robia Vaši užívatelia na sieti? Roman Tuchyňa, CSA

Experimentation driven traffic monitoring and engineering research

TRILL Large Layer 2 Network Solution

CISCO INFORMATION TECHNOLOGY AT WORK CASE STUDY: CISCO IOS NETFLOW TECHNOLOGY

NfSen Plugin Supporting The Virtual Network Monitoring

Flow Analysis Versus Packet Analysis. What Should You Choose?

How To Set Up Foglight Nms For A Proof Of Concept

NTT - A global IPv6 deployment case study

How To Create A Network Monitoring System (Flowmon) In Avea-Tech (For Free)

Virtual Machine in Data Center Switches Huawei Virtual System

50. DFN Betriebstagung

ICND2 NetFlow. Question 1. What are the benefit of using Netflow? (Choose three) A. Network, Application & User Monitoring. B.

Optimizing Data Center Networks for Cloud Computing

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

ITL BULLETIN FOR JANUARY 2011

STANDPOINT FOR QUALITY-OF-SERVICE MEASUREMENT

Service Description DDoS Mitigation Service

Detecting rogue systems

EAGLE EYE IP TAP. 1. Introduction

Transport and Network Layer

Research on Errors of Utilized Bandwidth Measured by NetFlow

LOG INTELLIGENCE FOR SECURITY AND COMPLIANCE

Cisco IOS Flexible NetFlow Technology

Cisco NetFlow Generation Appliance (NGA) 3140

Game changing Technology für Ihre Kunden. Thomas Bürgis System Engineering Manager CEE

Comprehensive IP Traffic Monitoring with FTAS System

5.0 Network Architecture. 5.1 Internet vs. Intranet 5.2 NAT 5.3 Mobile Network

Innovative, High-Density, Massively Scalable Packet Capture and Cyber Analytics Cluster for Enterprise Customers

RAVEN, Network Security and Health for the Enterprise

The Purview Solution Integration With Splunk

DDoS Protection. How Cisco IT Protects Against Distributed Denial of Service Attacks. A Cisco on Cisco Case Study: Inside Cisco IT

Craig Labovitz, Scott Iekel-Johnson, Danny McPherson Arbor Networks Jon Oberheide, Farnam Jahanian University of Michigan

NetFlow use cases. ICmyNet / NetVizura. Miloš Zeković, milos.zekovic@soneco.rs. ICmyNet Chief Customer Officer Soneco d.o.o.

FlowMon. Complete solution for network monitoring and security. INVEA-TECH

Service Assurance based on Packet Capture

Network Security Monitoring and Behavior Analysis Pavel Čeleda, Petr Velan, Tomáš Jirsík

IPv6 SECURITY. May The Government of the Hong Kong Special Administrative Region

Multicast monitoring and visualization tools. A. Binczewski R. Krzywania R. apacz

Strategies for Getting Started with IPv6

Introduction to IP v6

Decoding DNS data. Using DNS traffic analysis to identify cyber security threats, server misconfigurations and software bugs

Broadband Network Architecture

SolarWinds. Understanding SolarWinds Charts and Graphs Technical Reference

464XLAT in mobile networks

Network Layers. CSC358 - Introduction to Computer Networks

Network Packet Monitoring Optimizations Powered By SDN

INCREASE NETWORK VISIBILITY AND REDUCE SECURITY THREATS WITH IMC FLOW ANALYSIS TOOLS

Open Source in Network Administration: the ntop Project

Traffic Analysis With Netflow. The Key to Network Visibility

Development of the FITELnet-G20 Metro Edge Router

Traffic Analysis with Netflow The Key to Network Visibility

The use of SNMP and other network management tools in UNINETT. Arne Øslebø March 4, 2014

NetFlow-Based Approach to Compare the Load Balancing Algorithms

464XLAT: Breaking Free of IPv4. APRICOT 2014

Industry Automation White Paper Januar 2013 IPv6 in automation technology

and reporting Slavko Gajin

Product Line Strategy Network Recorder and Traffic Visibility Market: A Case Study

Development of an IPv6 Honeypot

Limitations of Packet Measurement

Web Analytics Understand your web visitors without web logs or page tags and keep all your data inside your firewall.

Massive Cloud Auditing using Data Mining on Hadoop

Monitoring of Tunneled IPv6 Traffic Using Packet Decapsulation and IPFIX

Challenges in NetFlow based Event Logging

Cover. White Paper. (nchronos 4.1)

IPv6 Network Management.

THE ADOPTION OF IPv6 *

Network Monitoring On Large Networks. Yao Chuan Han (TWCERT/CC)

Chapter 3. Enterprise Campus Network Design

Intelligent Load Balancing SSL Acceleration and Equalizer v7.0

An apparatus for P2P classification in Netflow traces

redborder IPS redborder Just common sense IPS overview Common sense

Internet Peering, IPv6, and NATs. Mike Freedman V Networks

SolarWinds Log & Event Manager

plixer Scrutinizer Competitor Worksheet Visualization of Network Health Unauthorized application deployments Detect DNS communication tunnels

Figure 1. perfsonar architecture. 1 This work was supported by the EC IST-EMANICS Network of Excellence (#26854).

The Value of Flow Data for Peering Decisions

Configuring and Managing Token Ring Switches Using Cisco s Network Management Products

vsphere Networking vsphere 6.0 ESXi 6.0 vcenter Server 6.0 EN

Hortonworks & SAS. Analytics everywhere. Page 1. Hortonworks Inc All Rights Reserved

vsphere Networking vsphere 5.5 ESXi 5.5 vcenter Server 5.5 EN

Network traffic monitoring and management. Sonia Panchen 11 th November 2010

IP Address Management: Smoothing the Way to Cloud-Based Services

Towards Smart and Intelligent SDN Controller

Secospace elog. Secospace elog

IPV6 流 量 分 析 探 讨 北 京 大 学 计 算 中 心 周 昌 令

Pacnet Premium Dedicated Internet Access Dedicated Internet Access for Web-Centric Enterprises

What s New in VMware vsphere 5.5 Networking

NetFlow: What is it, why and how to use it? Miloš Zeković, ICmyNet Chief Customer Officer Soneco d.o.o.

Transcription:

Passive Measurement in CSTNET Chunjing Han Aug. 2013 CSTNET, CNIC

Topics 1. Passive measurement systems introduction in CSTNET 2. Large - scale distributed traffic analysis system in IPv6

1, Passive measurement systems introduction in CSTNET

Background introduction IPv4 address will soon be depleted the Asia-Pacific region(april 2011) In the last three years, the number of ipv4 addresses assigned has a downward trend in China. This figure comes from CNNIC We need migrate to the IPv6 network and do not wait

Background introduction China Next Generation Internet (CNGI) IPv6 high-speed network IPv4-IPv6 dual network and support IPv6 in the whole CSTNET Traffic increasing continuously, congestion link, IPv6 ARP attack No-commercial IPv6 capable network management and traffic monitoring system We need monitor IPv6 traffic analyzers

Passive measurement systems CNMS Cloud network management system LDTM Large - scale distributed network monitoring system

Large - scale distributed traffic analysis system

LDTM( Large scale distribution traffic monitor) Netflow and DPI technology Goal: IPv6 support and can monitor the backbone and boundary of CSTNET Using cloud plus probe to implement LDTM Cloud: collect, process, and merge the raw flows, storage the aggregated records, and provide visual service. probe: create the improved Netflow packets and send network data to Cloud.

One cloud processing center, multi probes Deployment of LDTM This is typical implementation of multi - tenant cloud services model the collecting servers web servers, database, storage device.

Multiple layers for traffic collector Software architecture of LDTM

Flexible deployments Software deployment

An uniform CMDB Distributed collector design model Distributed collectors regularly synchronize the configuration from the CMDB, guarantee the correct monitoring scope of links and monitor objects Using the multi-process data loader tools and data dispatch map, to load big block data into the database cluster correctly and quickly

Key technology Property of IP address Continent, country, city, organization, customer information Enrich this information to each raw flows real-time Advance a IPv4-IPv6 attribution information searching algorithm based Patricia Tree 128 bits IPv6 address Provide uniform interface for IPv4&IPv6 A root node and two sub-tree Left IPv4 sub-tree Right IPv6 sub-tree

Key technology Aggregate huge raw flow recording Time granularity: min, hour, day, week, month Function aggregation: continent, country, protocol, application, host, session, packet size Advance the visual link concept: merge the traffic of multiple links as a visual link Long-term storing the raw flow records Create the raw flow file every five minutes Put it in the exclusive storage resource and do not occupy the space of the collecting servers.

Key technology Storage technology improvement for massive data Parallel database and database clusters Min granularity record small files stand-alone database Hour, day, week and month granularity record cluster big files database Cluster GBase 8a MPP GCluster sg01 sg02 sg03 sg04 192.168.100.11 192.168.100.12 192.168.100.13 159.226.61.24 192.168.100.14 192.168.100.15 192.168.100.16 192.168.100.17 192.168.100.18 千 兆 局 域 网 数 据 分 发 机 &8a 单 机 & 后 台 服 务 器 159.226.61.31 192.168.100.32 159.226.61.48 192.168.100.33

Features list Traffic weather map Distribution analysis Top N analysis Configuration Overview volume Top host Collecting Application Top session Exporter Organization Top protocol Link Region Continents Packe size Raw flows research IP utilization IP location Visual link Monitor object Application Traffic billing

Traffic weather map A geo-view traffic distribution Two levels of zoom: continent, region The IPv6 and IPv4 view separately Traffic of Top IP session, organization and region distribution,by using threedimensional flex model

Traffic distibution and Top N Organization distribution Top IPv6 address Top IP session Application distribution

Raw flow analysis Our can display a back trace of the current and history transferring flows. Enrich the raw flow using the GeoIP and institutes information of CSTNET. For IPv6, information of GeoIP is very limit. Provide the filter configuration of IP,port, protocol and link Provide downloading function of the raw flow records

Active IP address statistic Active IP address statistic is very important to evaluate the IP utilization. A statistics once a month---the active and inactive IP address We have stored the result in to the database and have not a good visualization for IPv6, due to the long address format and huge number of inactive IP address A time-consuming work

Traffic billing For the ISP and customer, LDTM provides a traffic billing inquiry of each customer in every day and month. For a customer, LDTM can query a special IP address traffic, including every application traffic and detail traffic records.

Providing a IP location service IP address location

Future work The active and passive measurement of IPv6 performance. Perfosonar Performance Probe passive data The active IPv6 address statistic A good algorithm to quickly get the result Suitable visualization, huge IPv6 address number Research of measurement method of IPv6 transition Dual stack Translation Tunnel THANK YOU