Analysis of Passive End-to-End Network Performance Measurements

Show full item record

Please use this identifier to cite or link to this item: http://hdl.handle.net/1853/14612

Title: Analysis of Passive End-to-End Network Performance Measurements
Author: Simpson, Charles Robert, Jr.
Abstract: NETI@home, a distributed network measurement infrastructure to collect passive end-to-end network measurements from Internet end-hosts was developed and discussed. The data collected by this infrastructure, as well as other datasets, were used to conduct studies on the behavior of the network and network users as well as the security issues affecting the Internet. A flow-based comparison of honeynet traffic, representing malicious traffic, and NETI@home traffic, representing typical end-user traffic, was conducted. This comparison showed that a large portion of flows in both datasets were failed and potentially malicious connection attempts. We additionally found that worm activity can linger for more than a year after the initial release date. Malicious traffic was also found to originate from across the allocated IP address space. Other security-related observations made include the suspicious use of ICMP packets and attacks on our own NETI@home server. Utilizing observed TTL values, studies were also conducted into the distance of Internet routes and the frequency with which they vary. The frequency and use of network address translation and the private IP address space were also discussed. Various protocol options and flags were analyzed to determine their adoption and use by the Internet community. Network-independent empirical models of end-user network traffic were derived for use in simulation. Two such models were created. The first modeled traffic for a specific TCP or UDP port and the second modeled all TCP or UDP traffic for an end-user. These models were implemented and used in GTNetS. Further anonymization of the dataset and the public release of the anonymized data and their associated analysis tools were also discussed.
Type: Dissertation
URI: http://hdl.handle.net/1853/14612
Date: 2007-01-02
Publisher: Georgia Institute of Technology
Subject: Network measurements end-to-end passive Internet
Electronic data processing Distributed processing
Internet
Electronic data interchange
Computer networks Mathematical models
Department: Electrical and Computer Engineering
Advisor: Committee Chair: Riley, George; Committee Member: Copeland, John; Committee Member: Fujimoto, Richard; Committee Member: Juang, Biing Hwang; Committee Member: Owen, Henry
Degree: Ph.D.

All materials in SMARTech are protected under U.S. Copyright Law and all rights are reserved, unless otherwise specifically indicated on or in the materials.

Files in this item

Files Size Format View
simpson_charles_r_200612_phd.pdf 744.0Kb PDF View/ Open

This item appears in the following Collection(s)

Show full item record