ACM Home Page
Please provide us with feedback. Feedback
Network discovery from passive measurements
Full text PdfPdf (552 KB)
Source
Applications, Technologies, Architectures, and Protocols for Computer Communication archive
Proceedings of the ACM SIGCOMM 2008 conference on Data communication table of contents
Seattle, WA, USA
SESSION: Measurement table of contents
Pages 291-302  
Year of Publication: 2008
ISBN:978-1-60558-175-0
Also published in ...
Authors
Brian Eriksson  University of Wisconsin - Madison, Madison, WI, USA
Paul Barford  University of Wisconsin - Madison, Madison, WI, USA
Robert Nowak  University of Wisconsin - Madison, Madison, WI, USA
Sponsors
ACM: Association for Computing Machinery
SIGCOMM: ACM Special Interest Group on Data Communication
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 25,   Downloads (12 Months): 251,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1402958.1402992
What is a DOI?

ABSTRACT

Understanding the Internet's structure through empirical measurements is important in the development of new topology generators, new protocols, traffic engineering, and troubleshooting, among other things. While prior studies of Internet topology have been based on active (traceroute-like) measurements, passive measurements of packet traffic offer the possibility of a greatly expanded perspective of Internet structure with much lower impact and management overhead. In this paper we describe a methodology for inferring network structure from passive measurements of IP packet traffic. We describe algorithms that enable 1) traffic sources that share network paths to be clustered accurately without relying on IP address or autonomous system information, 2) topological structure to be inferred accurately with only a small number of active measurements, 3) missing information to be recovered, which is a serious challenge in the use of passive packet measurements. We demonstrate our techniques using a series of simulated topologies and empirical data sets. Our experiments show that the clusters established by our method closely correspond to sources that actually share paths. We also show the trade-offs between selectively applied active probes and the accuracy of the inferred topology between sources. Finally, we characterize the degree to which missing information can be recovered from passive measurements, which further enhances the accuracy of the inferred topologies.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
The Honeynet Project. http://www.honeynet.org/, 2008.
 
2
 
3
M. Bailey, E. Cooke, F. Jahanian, J. Nazario, and D. Watson. The Internet Motion Sensor: A Distributed Blackhole Monitoring System. In Proceedings of The Network and Distributed Security Symposium (NDSS '05), San Diego, CA, January 2005.
4
 
5
CAIDA. The Skitter Project. http://www.caida.org/tools/measurement/skitter/, 2007.
6
7
8
 
9
 
10
C. Fraleigh, S. Moon, B. Lyles, C. Cotton, M. Khan, D. Moll, R. Rockell, T. Seely, and C. Diot. Packet-Level Traffic Measurements from the Sprint IP Backbone. IEEE Network, 17(6), Nov.-Dec. 2003.
 
11
 
12
P. Francis, S. Jamin, V. Paxson, D. Bryniewicz, and Y. Jin. An Architecture for a Global Internet Host Distance Estimation Service. In Proceedings of IEEE INFOCOM '99, New York, NY, April 1999.
 
13
Z. Ghahramani and M. Jordan. Supervised Learning from Incomplete Data via the EM Approach. In Advances in Neural Information Processing, 1994.
 
14
Z. Ghahramani and M. I. Jordan. Supervised learning from incomplete data via the EM approach. Advances in Neural Information Processing Systems 6 (NIPS'94), 1994.
 
15
R. Govindan and H. Tangmunarunkit. Heuristics for Internet Map Discovery. In Proceedings of IEEE INFOCOM '00, Tel Aviv, Israel, March 2000.
16
 
17
18
19
20
 
21
B. Lyon. The opte project. http://opte.org, January 2008.
22
 
23
24
 
25
E. Ng and H. Zhang. Predicting Internet Network Distance with Coordinate-baseed Approaches. In Proceedings of IEEE INFOCOM '02, New York, NY, April 2002.
 
26
Packetdesign. Route Explorer. http://www.packetdesign.com/, 2008.
27
 
28
29
 
30
31
 
32
N. Spring, D. Wetherall, and T. Anderson. Reverse Engineering the Internet. In Proceedings of Hotnets-II, Cambridge, MA, November 2003.
33
 
34
V. Yegneswaran, P. Barford, and D. Plonka. On the Design and Use of Internet Sinks for Network Abuse Monitoring. In Proceedings of Recent Advances on Intrusion Detection (RAID '04), Sophia, France, September 2004.

Collaborative Colleagues:
Brian Eriksson: colleagues
Paul Barford: colleagues
Robert Nowak: colleagues