The paper covers the centralized analysis of geographically-distributed network traffic. Traffic capture techniques, captured traffic delivery,aggregation, analysis and decision-making are presented. A special GNU/Linux distribution with integrated PF RING technology is created. It makes possible successful hi-speed (lGb/s) traffic capture. The captured traffic delivery system consists of two parts: client(s) and server. Both applications use encryption methods to transport captured traffic. The encryption methods are virtually unlimited due to the extensible encryption primitives. By default, a probabilistic stream cryptosystem called libpssc is used. After decryption, all the captured traffic is directed to a processing center where it becomes available for analysis. The processing center allows to plug in at real-time special independent plugins which analyze the traffic according to a criteria. Many plugins can work at once. Pilot implementation details and other results are reported also
Download file
Counter downloads: 94
- Title CENTRALIZED ANALYSIS OF GEOGRAPHICALLY-DISTRIBUTED NETWORK TRAFFIC
- Headline CENTRALIZED ANALYSIS OF GEOGRAPHICALLY-DISTRIBUTED NETWORK TRAFFIC
- Publesher
Tomsk State University
- Issue Prikladnaya Diskretnaya Matematika - Applied Discrete Mathematics 2(2)
- Date:
- DOI
Keywords
анализ , захват трафика , сетевой трафик Authors
References
http://ru.wikipedia.org/wiki/BSD
http://libnids.sourceforge.net/
Колегов Д.Н. Общая схема вероятностной поточной шифрсистемы // Вестник ТГУ. Приложение. 2006. № 17. С. 112 -114.
Агибалов Г.П. Вероятностные схемы симметричного поточного шифрования над конечным полем // Вестник ТГУ. Приложение. 2005. № 14. С. 39 - 42.
http://www.nmon.net/nTap.html
http://www.nmon.net/nMirror.html
http://www.ntop.org/PF_RING.html
<http://www.tcpdump.org/>
<http://www.winpcap.org/>
http://public.lanl.gov/cpw/ http://www.nmon.net/nCap.html

CENTRALIZED ANALYSIS OF GEOGRAPHICALLY-DISTRIBUTED NETWORK TRAFFIC | Prikladnaya Diskretnaya Matematika - Applied Discrete Mathematics. 2008. № 2(2).
Download full-text version
Download fileCounter downloads: 410