Tutorial about Passive Network Traffic Monitoring


Dear All,

I would like to inform you about a Tutorial which will be organised by the
LOBSTER project about the passive network traffic monitoring.

The tutorial will be held after the RIPE meeting in Stockholm (6 May
2005, afternoon), so it could be specially  interesting for those of you
who are participating in the RIPE meeting.

Please find more information below. If you have any questions about this
event, please don't hesitate to contact me!

Best regards,

 Baiba

-------------------------------------------------
Baiba Kaskina
Project Development Officer

TERENA Secretariat
Singel 468 D
1017 AW Amsterdam
Tel +31-20-530 44 88
-------------------------------------------------

LOBSTER Tutorial @ RIPE Meeting
Title: Passive Network Traffic Monitoring

6 May 2005 (afternoon) Stockholm, Sweden
in conjunction with the RIPE 50 Meeting.
(Participating in the RIPE meeting is not compulsory in order to attend
the tutorial.)

This tutorial is free of charge but you need to register:
http://www.terena.nl/events/?eventID=133

Abstract: The target of this tutorial is to introduce network managers,
network administrators, to the principles and practice of passive network
traffic monitoring, i.e. monitoring based on full packet capture and
inspection. The tutorial will cover several aspects related to full packet
passive monitoring, including (i) hardware support, (ii) software tools,
and (iii) higher level applications. The tutorial will start with the
current-state-of-the-art, review off-the-self solutions and continue with
results from recent efforts of the research community. This tutorial is
organized by the consortium of LOBSTER a European IST Project on
Large-Scale Monitoring of Broadband Internet Infrastructures.

The detailed outline of the tutorial is the following:

1. Introduction - What is passive monitoring? - by Evangelos Markatos,
FORTH
    * Differences between passive and active monitoring
    * Full packet vs. header/stats only passive monitoring
2. Full packet inspection
    * Current solutions:
          o pcap - by Herbert Bos, VUA
    * New approaches:
          o MAPI - by Evangelos Markatos, FORTH
          o FFPF - by Herbert Bos, VUA
    * Hardware support:
          o Combo - by Vladimir Smotlacha, CESNET
          o DAG - by Ian Graham, ENDACE
3. Flow-level (header-only) passive monitoring
    * General introduction:
          o NetFlow and IPFIX - by Arne Oslebo, UNINETT
    * NetFlow Applications:
          o Stager - by Arne Oslebo, UNINETT
          o NERD - by Rurger Coolen, TNO
4. Summary, Conclusions and Future trends - by Arne Oslebo, UNINETT

More information:
http://www.ist-lobster.org/events/tutorial-2005.html
http://www.ist-lobster.org/


----------------------------------------------------------
This mail was distributed via lobster-news@xxxxxxxxxxxxxxxx
To unsubscribe, visit the following URI:
http://www.ist-lobster.org/announcements.