CPL - Chalmers Publication Library
| Utbildning | Forskning | Styrkeområden | Om Chalmers | In English In English Ej inloggad.

Differences between In- and Outbound Internet Backbone Traffic

Wolfgang John (Institutionen för data- och informationsteknik, Datorteknik (Chalmers)) ; Sven Tafvelin (Institutionen för data- och informationsteknik, Datorteknik (Chalmers))
TERENA Networking Conference 2007, Copenhagen, DK (2007)
[Konferensbidrag, refereegranskat]

Contemporary backbone-traffic is analyzed with respect to behaviour differences between inbound and outbound Internet traffic. For the analysis, 146 traffic traces of 20 minutes duration have been collected in April 2006, carrying 10.7 billion frames and 7.5 TB of data. Significant directional differences, among others found in IP fragmentation, TCP termination behaviour and TCP options usage, are pointed out and discussed on different protocol levels (IP, TCP and UDP). The analysis includes a focus on TCP connection properties, yielding P2P and malicious traffic as main reasons for the differences. The results are relevant for a better understanding of how applied network protocols are used in an operative environment. Furthermore, a quantification of malicious traffic provides related research fields, such as network security or intrusion detection, with important insights.

Nyckelord: Internet Measurement, Directional Traffic Differences, TCP Connection Analysis, Network Anomalies



Denna post skapades 2007-07-19. Senast ändrad 2013-08-05.
CPL Pubid: 44320