Distributed network analysis using TOPAS and Wireshark

Gerhard Münz, Georg Carle

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

18 Scopus citations

Abstract

Distributed network analysis deals with the inspection of traffic observed at various locations in the network. The conventional approach is to deploy a full-fledged network analyzer at every observation point, which allows exhaustive examinations, but at the same time is a very costly solution. In this paper, we present an alternative approach using packet data exported by PSAMP and Flexible Netflow devices, such as routers, switches, and monitoring probes. Exported packet records are received by the real-time network analysis framework TOPAS and examined by the open-source network analyzer Wireshark. Monitoring devices are configured with a Monitor Manager in order to export only data needed to achieve the analysis goal. Apart from an architectural description, this paper contains the results of experimental performance evaluations and a discussion on the advantages and limitations of our approach.

Original languageEnglish
Title of host publication2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08
Pages161-164
Number of pages4
DOIs
StatePublished - 2008
Externally publishedYes
Event2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08 - Salvador da Bahia, Brazil
Duration: 7 Apr 200811 Apr 2008

Publication series

Name2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08

Conference

Conference2008 IEEE Network Operations and Management Symposium Workshops - NOMS 08
Country/TerritoryBrazil
CitySalvador da Bahia
Period7/04/0811/04/08

Fingerprint

Dive into the research topics of 'Distributed network analysis using TOPAS and Wireshark'. Together they form a unique fingerprint.

Cite this