Characterization and Classification of Internet Backbone Traffic
Doctoral thesis, 2010

We contribute to an improved understanding of Internet traffic characteristics by measuring and analyzing modern Internet backbone data. We start the thesis with an overview of several important considerations for passive Internet traffic collection on large-scale network links. The lessons learned from a successful measurement project on academic Internet backbone links can serve as guidelines to others setting up and performing similar measurements. The data from these measurements are the basis for the analyses made in this thesis. As a first result we present a detailed characterization of packet headers, which reveals protocol-specific features and provides a systematic survey of packet header anomalies. The packet-level analysis is followed by a characterization on the flow-level, where packets are correlated according to their communication endpoints. We propose a method and accompanying metrics to assess routing symmetry on a flow-level based on passive measurements. This method will help to improve traffic analysis techniques. We used the method on our data, and the results suggest that routing symmetry is uncommon on non- edge Internet links. We then confirm the predominance of TCP as the transport protocol in backbone traffic. However, we observe an increase of UDP traffic during the last few years, which we attribute to P2P signaling traffic. We also analyze further flow characteristics such as connection establishment and termination behavior, which reveals differences among traffic from various classes of applications. These results show that there is a need to make a more detailed analysis, i.e., classification of traffic according to network application. To accomplish this, we review state-of-the-art traffic classification approaches and subsequently propose two new methods. The first method provides a payload-independent classification of aggregated traffic based on connection patterns. This provides a rough traffic decomposition in a privacy sensitive way. Second, we present a classification method for fine-grained protocol identification by utilizing statistical packet and flow features. Preliminary results indicate that this method is capable of accurate classification in a simple and efficient way. We conclude the thesis by discussing limitations in current Internet measurement research. Considering the role of the Internet as a critical infrastructure of global importance, a detailed understanding of Internet traffic is essential. This thesis presents methods and results contributing additional perspectives on global Internet characteristics at different levels of granularity.

Characterization

Measurement

Backbone

Internet

Classification

Traffic

Passive

HA2 (Hörsalsvägen 4)
Opponent: Prof. Vern Paxson, University of California, Berkeley, USA

Author

Wolfgang John

Chalmers, Computer Science and Engineering (Chalmers), Networks and Systems (Chalmers)

Statistical Protocol IDentification with SPID: Preliminary Results

Swedish National Computer Networking Workshop,;(2009)

Paper in proceeding

Estimating Routing Symmetry on Single Links by Passive Flow Measurements

IWCMC'10: 6th International Wireless Communications & Mobile Computing Conference,,;(2010)p. 473--478-

Paper in proceeding

Trends and Differences in Connection-behavior within Classes of Internet Backbone Traffic

Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics),;Vol. 4979/2008(2008)p. 192-201

Paper in proceeding

Analysis of Internet Backbone Traffic and Header Anomalies Observed

IMC '07: Proceedings of the 7th ACM SIGCOMM conference on Internet measurement,;(2007)p. 111-116

Paper in proceeding

Differences between In- and Outbound Internet Backbone Traffic

TERENA Networking Conference 2007, Copenhagen, DK,;(2007)

Paper in proceeding

Heuristics to Classify Internet Backbone Traffic based on Connection Patterns

ICOIN '08: Proceedings of the 22nd International Conference on Information Networking,;(2008)

Paper in proceeding

State of the Art in Traffic Classification: A Research Review

PAM '09: 10th International Conference on Passive and Active Measurement, Student Workshop,;(2009)

Conference poster

Detection of malicious Traffic on Backbone links via Packet Header Analysis

Campus-Wide Information Systems,;Vol. 25(2008)p. 342 - 358

Journal article

Analysis of UDP Traffic Usage on Internet Backbone Links

Saint '09: Ninth Annual International Symposium on Applications and the Internet,;(2009)p. 280 - 281

Paper in proceeding

Passive Internet Measurement: Overview and Guidelines based on Experiences

Computer Communications,;Vol. 33(2010)p. 533-550

Journal article

Subject Categories (SSIF 2011)

Computer Engineering

ISBN

978-91-7385-363-7

Doktorsavhandlingar vid Chalmers tekniska högskola. Ny serie: 3044

Technical report D - Department of Computer Science and Engineering, Chalmers University of Technology and Göteborg University: 65

HA2 (Hörsalsvägen 4)

Opponent: Prof. Vern Paxson, University of California, Berkeley, USA

More information

Created

10/8/2017