ACM Home Page
Please provide us with feedback. Feedback
Packet trace manipulation rramework for test labs
Full text PdfPdf (165 KB)
Source Internet Measurement Conference archive
Proceedings of the 4th ACM SIGCOMM conference on Internet measurement table of contents
Taormina, Sicily, Italy
SESSION: Measurement tools table of contents
Pages: 251 - 256  
Year of Publication: 2004
ISBN:1-58113-821-0
Authors
Andy Rupp  Ruhr-Universität Bochum
Holger Dreger  TU München
Anja Feldmann  TU München
Robin Sommer  TU München
Sponsors
SIGCOMM: ACM Special Interest Group on Data Communication
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 4,   Downloads (12 Months): 17,   Citation Count: 2
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1028788.1028821
What is a DOI?

ABSTRACT

Evaluating network components such as network intrusion detection systems, firewalls, routers, or switches suffers from the lack of available network traffic traces that on the one hand are appropriate for a specific test environment but on the other hand have the same characteristics as actual traffic. Instead of just capturing traffic and replaying the trace, we identify a set of packet trace manipulation operations that enable us to generate a trace bottom-up: our trace primitives can be traces from different environments or artificially generated ones; our basic operations include merging of two traces, moving a flow across time, duplicating a flow, and stretching a flow's time-scale. After discussing the potential as ell as the dangers of each operation with respect to analysis at different protocol layers, we present a framework within which these operations can be realized and show an example configuration for our prototype.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Advanced pipe and filters architecture &TTM plugin package project.http://www.net.informatik.tu-muenchen.de/ rdc/.
 
2
S.Bajaj, L.Breslau, D.E trin, K.Fall, S.Floyd, P.Haldar, M.Handley, A.Helmy, J.Heidemann, P.Huang, S.Kumar, S.McCanne, R.Rejaie,P.Sharma, S.Shenker, K.Varadhan, H.Yu, Y.Xu, and D.Zappala. Virtual InterNetwork Testbed: Status and research agenda. Technical Report 98--678,University of Southern California,July 1998.
 
3
 
4
Cisco Netflow. http://www.cisco.com/warp/public/732/Tech/nmp/netflow/index.shtml
5
 
6
ENDACE measurement systems. http://www.endace.com/.
7
 
8
A. Feldmann, H. Kong, O. Maennel, and A. Tudor. Measuring BGP pas-through time. In Proc. of the Passive and Active Measurement Workshop (PAM),2004.
9
 
10
11
 
12
C. Kreibich. Design and Implementation of Netdude, a Framework for Packet Trace Manipulation. In Proc. Usenix Technical Conference, Freenix Track 2004.
 
13
 
14
S. McCanne and V. Jacob on. The bsd packet filter: A new architecture for user-level packet capture. In U. Association, editor, Proc. Winter 1993 USENIX Conference USENIX Association,1993.
 
15
P. Phaal, S. Panchen, and N. McKee. sFlow,2001. RFC 3176.
 
16
A. Rupp. A Software System for Packet Trace Customization with Application to NIDS Evaluation.Master 'thesis, Universit ät de Saarlandes,Germany,2004.
 
17
The tcpdump libpcap project. http://www.tcpdump.org/.
 
18
The tcpreplay project. http://tcpreplay.sourceforge.net/.
 
19
M.Völter. PluggableComponent -A Pattern for Interactive System Configuration. In Proc. of the 4th European Conference on Pattern Languages of Programming and Computing 1999.


Collaborative Colleagues:
Andy Rupp: colleagues
Holger Dreger: colleagues
Anja Feldmann: colleagues
Robin Sommer: colleagues