Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Assessing the quality of packet-level traces collected on internet backbone links
Chalmers University of Technology, Sweden.ORCID iD: 0000-0001-9536-4269
2012 (English)In: Lect. Notes Comput. Sci., 2012, p. 184-198Conference paper, Published paper (Refereed)
Abstract [en]

The quality of captured traffic plays an important role for decisions made by systems like intrusion detection/prevention systems (IDS/IPS) and firewalls. As these systems monitor network traffic to find malicious activities, a missing packet might lead to an incorrect decision. In this paper, we analyze the quality of packet-level traces collected on Internet backbone links using different generations of DAG cards. This is accomplished by inferring dropped packets introduced by the data collection system with help of the intrinsic structural properties inherently provided by TCP traffic flows. We employ two metrics which we believe can detect all kinds of missing packets: i) packets with ACK numbers greater than the expected ACK, indicating that the communicating parties acknowledge a packet not present in the trace; and ii) packets with data beyond the receiver's window size, which with a high probability, indicates that the packet advertising the correct window size was not recorded. These heuristics have been applied to three large datasets collected with different hardware and in different environments. We also introduce flowstat, a tool developed for this purpose which is capable of analyzing both captured traces and real-time traffic. After assessing more than 400 traces (75M bidirectional flows), we conclude that at least 0.08% of the flows have missing packets, a surprisingly large number that can affect the quality of analysis performed by firewalls and intrusion detection/prevention systems. The paper concludes with an investigation and discussion of the spatial and temporal aspects of the experienced packet losses and possible reasons behind missing data in traces. 

Place, publisher, year, edition, pages
2012. p. 184-198
Keywords [en]
firewall, intrusion detection/prevention system, measurement errors, packet drop, Traffic measurement, Bi-directional flows, Data collection system, High probability, Internet backbone, Large datasets, Malicious activities, Missing data, Network traffic, Packet drops, Real time traffics, Systems monitor, TCP traffic, Temporal aspects, Traffic measurements, Window Size, Computer system firewalls, Internet, Packet loss, Information technology
National Category
Natural Sciences
Identifiers
URN: urn:nbn:se:ri:diva-56962DOI: 10.1007/978-3-642-34210-3_13Scopus ID: 2-s2.0-84868350506ISBN: 9783642342097 (print)OAI: oai:DiVA.org:ri-56962DiVA, id: diva2:1612776
Conference
31 October 2012 through 2 November 2012, Karlskrona
Available from: 2021-11-19 Created: 2021-11-19 Last updated: 2025-09-23Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Sangchoolie, Behrooz

Search in DiVA

By author/editor
Sangchoolie, Behrooz
Natural Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 32 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf