An Infrastructure for Flow-Level Network-Wide Traffic Measurement Based on Netflow

GAO Lei,YANG Jia-hai,ZHANG Hui,LI Fu-liang,ZHANG Bin
DOI: https://doi.org/10.3969/j.issn.1001-7445.2011.z1.017
2011-01-01
Abstract:The fine-grained flow level measurement is getting increasing demand in recent years.Though it fails to be a generic solution for its biased sampling,Netflow is promising for its compatibility with prevalent routers and its convenience to perform direct flow level measurement of both IPv4 and IPv6 traffic.Traditional flow level measurement systems based on Netflow are mostly centralized and each of them independently performs traffic analysis of its local flow records without any coordination in a large-scale network,suffering from unbalancing workload and bad scalability.In this paper we present the construction of FlowInfra which is a scalable infrastructure for network-wide flow measurement of pure IPv6 flow records from Netflow v9 exports.Through the assessment of its performance and flexible features,we show that FlowInfra achieved enhanced ability and robustness to perform network-wide flow level measurement.In addition,based on the observation on CERNET2's traffic data,we propose a new method to identify P2P traffic over IPv6.
What problem does this paper attempt to address?