Tutorial about Passive Network Traffic Monitoring
- Subject: [lobster-news] Tutorial about Passive Network Traffic Monitoring
- From: Baiba Kaskina <baiba@xxxxxxxxx>
- Date: Wed, 23 Mar 2005 10:37:35 +0100 (CET)
Dear All, I would like to inform you about a Tutorial which will be organised by the LOBSTER project about the passive network traffic monitoring. The tutorial will be held after the RIPE meeting in Stockholm (6 May 2005, afternoon), so it could be specially interesting for those of you who are participating in the RIPE meeting. Please find more information below. If you have any questions about this event, please don't hesitate to contact me! Best regards, Baiba ------------------------------------------------- Baiba Kaskina Project Development Officer TERENA Secretariat Singel 468 D 1017 AW Amsterdam Tel +31-20-530 44 88 ------------------------------------------------- LOBSTER Tutorial @ RIPE Meeting Title: Passive Network Traffic Monitoring 6 May 2005 (afternoon) Stockholm, Sweden in conjunction with the RIPE 50 Meeting. (Participating in the RIPE meeting is not compulsory in order to attend the tutorial.) This tutorial is free of charge but you need to register: http://www.terena.nl/events/?eventID=133 Abstract: The target of this tutorial is to introduce network managers, network administrators, to the principles and practice of passive network traffic monitoring, i.e. monitoring based on full packet capture and inspection. The tutorial will cover several aspects related to full packet passive monitoring, including (i) hardware support, (ii) software tools, and (iii) higher level applications. The tutorial will start with the current-state-of-the-art, review off-the-self solutions and continue with results from recent efforts of the research community. This tutorial is organized by the consortium of LOBSTER a European IST Project on Large-Scale Monitoring of Broadband Internet Infrastructures. The detailed outline of the tutorial is the following: 1. Introduction - What is passive monitoring? - by Evangelos Markatos, FORTH * Differences between passive and active monitoring * Full packet vs. header/stats only passive monitoring 2. Full packet inspection * Current solutions: o pcap - by Herbert Bos, VUA * New approaches: o MAPI - by Evangelos Markatos, FORTH o FFPF - by Herbert Bos, VUA * Hardware support: o Combo - by Vladimir Smotlacha, CESNET o DAG - by Ian Graham, ENDACE 3. Flow-level (header-only) passive monitoring * General introduction: o NetFlow and IPFIX - by Arne Oslebo, UNINETT * NetFlow Applications: o Stager - by Arne Oslebo, UNINETT o NERD - by Rurger Coolen, TNO 4. Summary, Conclusions and Future trends - by Arne Oslebo, UNINETT More information: http://www.ist-lobster.org/events/tutorial-2005.html http://www.ist-lobster.org/ ---------------------------------------------------------- This mail was distributed via lobster-news@xxxxxxxxxxxxxxxx To unsubscribe, visit the following URI: http://www.ist-lobster.org/announcements.

