2006 IEEE International Conference on Communications 2006
DOI: 10.1109/icc.2006.254793
|View full text |Cite
|
Sign up to set email alerts
|

Passive Identification and Analysis of TCP Anomalies

Abstract: Abstract-In this paper we focus on passive measurements of TCP traffic, main component of nowadays traffic. We propose a heuristic technique for the classification of the anomalies that may occur during the lifetime of a TCP flow, such as out-ofsequence and duplicate segments. Since TCP is a closed-loop protocol that infers network conditions by means of losses and reacts accordingly, the possibility of carefully distinguishing the causes of anomalies in TCP traffic is very appealing, since it may be instrumen… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

1
14
0

Year Published

2007
2007
2023
2023

Publication Types

Select...
7
1

Relationship

2
6

Authors

Journals

citations
Cited by 15 publications
(15 citation statements)
references
References 9 publications
1
14
0
Order By: Relevance
“…The first probe has been connected to one of the two PoP L2-switches, that was configured to replicate all traffic coming in and going out through the links connecting the PoP backbone router. Tstat was directly run on the probe so that live traffic measurements are taken, and results can be observed from the Web through Tstat Web interface [14]. An average load of 100Mbps full-duplex with peaks up to 500Mbps of traffic has been processed for more than three weeks.…”
Section: Measurement Resultsmentioning
confidence: 99%
See 2 more Smart Citations
“…The first probe has been connected to one of the two PoP L2-switches, that was configured to replicate all traffic coming in and going out through the links connecting the PoP backbone router. Tstat was directly run on the probe so that live traffic measurements are taken, and results can be observed from the Web through Tstat Web interface [14]. An average load of 100Mbps full-duplex with peaks up to 500Mbps of traffic has been processed for more than three weeks.…”
Section: Measurement Resultsmentioning
confidence: 99%
“…All the developed algorithms have been implemented in Tstat [14]. Tstat is an IP networks monitoring and performance analysis tool developed by the Telecommunication Networks Group at the Politecnico di Torino.…”
Section: Measurement Methodologymentioning
confidence: 99%
See 1 more Smart Citation
“…All the developed algorithms have been implemented in Tstat [15]. Tstat is an IP networks monitoring and performance analysis tool developed by the Telecommunication Networks Group at Politecnico di Torino; Tstat is a free open-software tool.…”
Section: Measurement Methodologymentioning
confidence: 99%
“…The probe node is based on high-end PCs running Linux, and has been installed in a PoP located in Torino, Italy. The first bytes of the packet payload are exposed to the Tstat [13] analyzer, that identifies the application generating each packet (see [10], [11] for details). We therefore distinguish the traffic in the following classes,…”
Section: Measurement Methodologymentioning
confidence: 99%