TY - GEN
T1 - Distributed network analysis using TOPAS and Wireshark
AU - Münz, Gerhard
AU - Carle, Georg
PY - 2008
Y1 - 2008
N2 - Distributed network analysis deals with the inspection of traffic observed at various locations in the network. The conventional approach is to deploy a full-fledged network analyzer at every observation point, which allows exhaustive examinations, but at the same time is a very costly solution. In this paper, we present an alternative approach using packet data exported by PSAMP and Flexible Netflow devices, such as routers, switches, and monitoring probes. Exported packet records are received by the real-time network analysis framework TOPAS and examined by the open-source network analyzer Wireshark. Monitoring devices are configured with a Monitor Manager in order to export only data needed to achieve the analysis goal. Apart from an architectural description, this paper contains the results of experimental performance evaluations and a discussion on the advantages and limitations of our approach.
AB - Distributed network analysis deals with the inspection of traffic observed at various locations in the network. The conventional approach is to deploy a full-fledged network analyzer at every observation point, which allows exhaustive examinations, but at the same time is a very costly solution. In this paper, we present an alternative approach using packet data exported by PSAMP and Flexible Netflow devices, such as routers, switches, and monitoring probes. Exported packet records are received by the real-time network analysis framework TOPAS and examined by the open-source network analyzer Wireshark. Monitoring devices are configured with a Monitor Manager in order to export only data needed to achieve the analysis goal. Apart from an architectural description, this paper contains the results of experimental performance evaluations and a discussion on the advantages and limitations of our approach.
UR - http://www.scopus.com/inward/record.url?scp=51149107168&partnerID=8YFLogxK
U2 - 10.1109/NOMSW.2007.27
DO - 10.1109/NOMSW.2007.27
M3 - Conference contribution
AN - SCOPUS:51149107168
SN - 9781424420674
T3 - 2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08
SP - 161
EP - 164
BT - 2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08
T2 - 2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08
Y2 - 7 April 2008 through 11 April 2008
ER -