See this document in CiteSeerX!

NetFlow: Information loss or win?  (Make Corrections)  
Robin Sommer and Anja Feldmann Saarland University, Saarbrucken, Germany...



  Home/Search   Context   Related

 
View or download:
icir.org/robin/papers/netflow.ps
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  icir.org/robin/papers/ (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: Operating a network without accurate traffic statistics is not desirable. Commonly used data sources are SNMP [1], flow-level data, e.g., CISCO's NETFLOW, or packet level data. The first data source provides low volume, coarse-grained, non-application specific data. The latter one provides high volume, fine-grain data and application specific information. NetFlow lies somewhere in between in terms of both: volume and level of detail. In this paper we ask the question how and how accurately can... (Update)

Active bibliography (related documents):   More   All
0.7:   NetFlow: Information Loss or Win? - Sommer, Feldmann (2002)   (Correct)
0.2:   Deriving Traffic Demands for Operational IP.. - Feldmann.. (2000)   (Correct)
0.2:   A Signal Analysis of Network Traffic Anomalies - Barford, Kline, Plonka, Ron (2002)   (Correct)

Similar documents based on text:
0.0:   Unknown -   (Correct)

BibTeX entry:   (Update)

@misc{ and-netflow,
  author = "Robin Sommer And",
  title = "NetFlow: Information loss or win?",
  url = "citeseer.ist.psu.edu/738216.html" }
Citations (may not include all citations):
261   Widearea internet traffic patterns and characteristics (context) - Thompson, Miller et al. - 1997
104   Deriving traffic demands for operational ip networks: Method.. - Feldmann, Greenberg et al. - 2000
66   A parameterizable methodology for internet traffic flow prof.. - Claffy, Braun et al. - 1995
65   Bro: A system for detecting network intruders in real-time - Paxson - 1999
59   On Calibrating Measurements of Packet Transit Times - Paxson - 1998
55   IP switching: ATM under IP - Newman, Minshall et al. - 1998
55   A simulation study of IP switching (context) - Lin, McKeown - 1997
34   Efficient policies for carrying Web traffic over flow-switch.. - Feldmann, Rexford et al. - 1998
30   Traffic flow measurement: Meter MIB (context) - Brownlee - 1999
29   Insertion, evasion, and denial of service: Eluding network i.. - Ptacek, Newsham - 1998
17   Characteristics of Network Traffic Flow Anomalies - Barford, Plonka - 2001
16   The OSU flow-tools package and CISCO netflow logs (context) - Fullmer, Romig - 2000
12   FlowScan: A network traffic flow reporting and visualization.. (context) - Plonka - 2000
11   SNMPv3 and RMON 1 and (context) - Stallings, SNMPv - 1999
6   RTFM: New attributes for traffic flow measurement (context) - Handelman, Stibler et al. - 1999
2   Flow-based Traffic Analysis at SWITCH - Leinen
http://www.cisco.com/warp/
http://www.caida
http://www.tcpdump.org
http://www.cs.wisc
http://www.python.org
http://www.gnutelliums.com
http://ita.ee.lbl.gov/html/
http://www.kazaa.com
http://www.caida
http://www.cisco.com/warp/public/

Documents on the same site (http://www.icir.org/robin/papers/):   More
Exploiting Independent State for Network Intrusion Detection - Sommer, Paxson (2004)   (Correct)
Enhancing Byte-Level Network Intrusion Detection Signatures.. - Sommer, Paxson (2003)   (Correct)
Operational Experiences with High-Volume - Network Intrusion Detection   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC