Wednesday, July 1, 2009

Analysis of Internet Backbone Traffic and Header Anomalies Observed

Authors: J Wolfgang, S Tafvelin

This is a comparison with their later paper.

Differences
  • length of study
    • this study collected data from spring 2006 (april), 7.5 TB data
    • their later study included data from spring 2006, and newer data from fall 2006 (september to november), 5 TB data
  • focus
    • this study: headers used and anomalies
    • their later study: traffic classes, also observed some header anomalies
This study:
  • ecn deployment is still small 0.2% of tested clients
  • more upd packets are fragmented (97%) than tcp (3%) for their incoming segments. not surprising since path mtu is for TCP only
Their later study:
  • p2p is more aggressive in using SACK
  • WS and TS is more established in http
Common:
This study represents the initial results of their overall study by focusing on headers and their effect on the applications being used. Their later paper presents a more in-depth study and presented the impact of the header anomalies in ways that can be used to improve the monitoring of applications using the network, and detection of malicious attacks being conducted

No comments:

Post a Comment