SlideShare a Scribd company logo
Network Monitoring
and Measurement
Definition
• Network traffic measurement is the
process of measuring the amount and type of traffic on a particular
network. This is especially important with regard to effective
bandwidth management.
• Network monitoring describes the use of a system
that constantly monitors a computer network for slow or failing
systems and that notifies the network administrator in case of
outages via email, pager or other alarms. It is a subset of the
functions involved in network management.
Motivation
★ Needs of service providers:
★Understand the behavior of their networks
★Provide fast, high-quality, reliable service to satisfy customers and thus reduce
churn rate
★Plan for network deployment and expansion
★SLA monitoring, Network security
★Usage-based billing for network users (like telephone calls)
★Marketing using CRM data
★ Needs of Customers:
★Want to get their money’s worth
★Fast, reliable, high-quality, secure, virus-free Internet access
Application
• Network Problem Determination and Analysis
• Traffic Report Generation
• Intrusion & Hacking Attack (e.g., DoS, DDoS) Detection
• Service Level Monitoring (SLM)
• Network Planning
• Usage-based Billing
• Customer Relationship Management (CRM)
• Marketing
The General Traffic Flow Measurement Process
Classification &
Flow Recording
Store
(TCPdump)
Observation
Point
PAYLOAD HEAD
PAYLOAD HEAD
PAYLOAD HEAD
PAYLOAD HEAD
Packet
Capturing
Filtering
Display
(Ethereal)
Sampling
Visualize
(FlowScan)
Analysis
by applications
(TE, attack
detect., QoS
monitoring,
accounting, …)
… other …
packets
Filtering
Sampling
flow records
flow records
packets
packets
flow records
flow
records
Problems
• Capturing Packets:
✴High-speed networks (Mbps ? Gbps ? Tbps)
✴High-volume traffic
✴Streaming media (Windows Media, Real Media, Quicktime)
✴P2P traffic
✴Network Security Attacks
• Flow Generation & Storage:
What packet information to save to perform various analysis?
How to minimize storage requirements?
• Analysis:
How to analyze and generate data needed quickly?
What kinds of info needs to be generated? -- Depends on applications
Goals
• Capture all packets
• Generate flows
• Store flows efficiently
• Analyze data efficiently
• Generate various reports or information that are suitable for various
application areas
Develop a flexible, scalable traffic monitoring and
analysis system for high-speed, high-volume, rich media
IP networks
Network Monitoring Metrics
• CAIDA Metrics Working Group (www.caida.org)
✴Latency
✴Packet Loss
✴Throughput
✴Link Utilization
✴Availability
• IETF’s IP Performance Metrics (IPPM) Working Group
✴Connectivity (RFC 2687)
✴One-Way Delay (RFC 2679)
✴One-Way Packet Loss (RFC 2680)
✴Round Trip Delay (RFC 2681)
✴Delay Variation
✴Bulk transfer capacity
One way loss
RT loss
One way delay
RT delay
Capacity
Bandwidth
Throughput
Delay variance
Network Monitoring
Metrics
Availability
Connectivity
Functionality
Loss
Delay
Utilization
• Availability: The percentage of a specified time interval during which
the system was available for normal use.
✤Connectivity: the physical connectivity of network elements.
✤Functionality: whether the associated system works well or not.
• Latency: The time taken for a packet to travel from a host to another.
✤Round Trip Delay = Forward transport delay + server delay + backward
transport delay
✤Ping is still the most commonly used to measure latency.
• Link Utilization over a specified interval is simply the throughput for the
link expressed as a percentage of the access rate.
Monitoring Method
• Active Monitoring
• Passive Monitoring
Active Monitoring
• Performed by sending test traffic into network
• Generate test packets periodically or on-demand
• Measure performance of test packets or responses
• Take the statistics
• Impose extra traffic on network and distort its behavior in
the process
• Test packet can be blocked by firewall or processed at low
priority by routers
• Mainly used to monitor network performance
Passive Monitoring
• Carried out by observing network traffic
• Collect packets from a link or network flow from a router
• Perform analysis on captured packets for various purposes
• Network device performance degrades by mirroring or flow export
• Used to perform various traffic usage/characterization
analysis/intrusion detection
Comparison of Monitoring
Approaches
Active monitoring Passive monitoring
Configuration Multi-point Single or multi-point
Data size Small Large
Network overhead Additional traffic - Device overhead
- No overhead if
splitter is used
Purpose Delay, packet loss,
availability
Throughput, traffic
pattern, trend, &
detection
CPU Requirement Low to Moderate High
Software in Network Monitoring and
Management
• EPM
• The ping program
• SNMP servers
• IBM AURORA Network Performance Profiling System
• Intellipool Network Monitor
• Jumpnode
• Microsoft Network Monitor 3
• MRTG
• Nagios (formerly Netsaint)
• Netdisco
• NetQoS
• NetXMS Scalable network and application monitoring system
Software in Network Monitoring and
Management
• Opennms
• PRTG
• Pandora (Free Monitoring System) - Network and Application Monitoring System
• PIKT
• RANCID - monitors router/switch configuration changes
• RRDtool
• siNMs by Siemens
• SysOrb Server & Network Monitoring System
• Sentinet3 - Network and Systems Monitoring Appliance
• ServersCheck Monitoring Software
• Cacti network graphing solution
• Zabbix - Network and Application Monitoring System
• Zenoss - Network and Systems Monitoring Platform
• Level Platforms - Software support for network monitoring

More Related Content

What's hot (20)

PPTX
Observability
Enes Altınok
 
PPTX
AWS Snowball
zekeLabs Technologies
 
PDF
Observability
Ebru Cucen Çüçen
 
PDF
게임 산업을 위한 네이버클라우드플랫폼(정낙수 클라우드솔루션아키텍트) - 네이버클라우드플랫폼 게임인더스트리데이 Naver Cloud Plat...
NAVER CLOUD PLATFORMㅣ네이버 클라우드 플랫폼
 
PPTX
Virtual private network(vpn)
sonalikasingh15
 
PPTX
AWS Virtual Private Cloud (VPC) in nutshell
Mohit Kumar
 
PPTX
The Top Outages of 2021: Analysis and Takeaways
ThousandEyes
 
PPTX
Data storage security in cloud computing
Sonali Jain
 
PDF
[Gaming on AWS] AWS 위에서의 Dev & Test, 그리고 비용 - 위메이드
Amazon Web Services Korea
 
PDF
Vpn ppt
Nikhila Pothukuchi
 
PDF
Sistemas de Recomendação - Parte 2
Ralph Rassweiler
 
PPTX
Introduction to Software Defined Networking (SDN)
Bangladesh Network Operators Group
 
PPTX
Software Defined Network (SDN)
Ahmed Ayman
 
PDF
CloudAnalyst: A CloudSim-based Tool for Modelling and Analysis of Large Scale...
ambitlick
 
PDF
Combining logs, metrics, and traces for unified observability
Elasticsearch
 
PDF
Introduction to Software Defined WANs
APNIC
 
PPT
firewall.ppt
ssuser530a07
 
PDF
Observability at Scale
Knoldus Inc.
 
PDF
Top Down Network Design - ebrahma.com
Pawan Sharma
 
PPTX
NTP Server - How it works?
Davoud Teimouri
 
Observability
Enes Altınok
 
AWS Snowball
zekeLabs Technologies
 
Observability
Ebru Cucen Çüçen
 
게임 산업을 위한 네이버클라우드플랫폼(정낙수 클라우드솔루션아키텍트) - 네이버클라우드플랫폼 게임인더스트리데이 Naver Cloud Plat...
NAVER CLOUD PLATFORMㅣ네이버 클라우드 플랫폼
 
Virtual private network(vpn)
sonalikasingh15
 
AWS Virtual Private Cloud (VPC) in nutshell
Mohit Kumar
 
The Top Outages of 2021: Analysis and Takeaways
ThousandEyes
 
Data storage security in cloud computing
Sonali Jain
 
[Gaming on AWS] AWS 위에서의 Dev & Test, 그리고 비용 - 위메이드
Amazon Web Services Korea
 
Sistemas de Recomendação - Parte 2
Ralph Rassweiler
 
Introduction to Software Defined Networking (SDN)
Bangladesh Network Operators Group
 
Software Defined Network (SDN)
Ahmed Ayman
 
CloudAnalyst: A CloudSim-based Tool for Modelling and Analysis of Large Scale...
ambitlick
 
Combining logs, metrics, and traces for unified observability
Elasticsearch
 
Introduction to Software Defined WANs
APNIC
 
firewall.ppt
ssuser530a07
 
Observability at Scale
Knoldus Inc.
 
Top Down Network Design - ebrahma.com
Pawan Sharma
 
NTP Server - How it works?
Davoud Teimouri
 

Similar to 1. Network monitoring and measurement-2.ppt (20)

PPTX
Network monitoring Project Proposal.pptx
IT18GOWSIKKKUMARK202
 
PPT
network-management Web base.ppt
AssadLeo1
 
PDF
Identify and Resolve Ntwork Problems.pdf
Meresa Hiluf`
 
DOCX
Computer Network Monitoring & Performance
Dmitry Ponomarenko
 
PDF
BSIT3CD_Continuation of Cyber incident response (1).pdf
StevenJoeBiago
 
PDF
Identify and resolve network problems
Abenezer Abiti
 
PPT
Chapter09
Muhammad Ahad
 
PDF
IRJET- Comparative Study on Network Monitoring Tools of Nagios Versus Hyp...
IRJET Journal
 
PPTX
Importance of Network Performance Monitoring
cPacket Networks
 
PPTX
Tune Up Your Network for the New Year
Savvius, Inc
 
PPT
Network monotoring
Programmer
 
PPTX
networkmonitoringtools-200615094423.pptx
kelvinzallan5
 
PDF
Week10
Hayato
 
PDF
Netscan and Networx for Management Bandwidth and Traffic with Simple Routing
TELKOMNIKA JOURNAL
 
PDF
Network visibility and control using industry standard sFlow telemetry
pphaal
 
PPTX
Network monitoring tools
QaswarBosan
 
PDF
Marvell Network Telemetry Solutions for Data Center and Enterprise Networks
Marvell
 
PDF
Lecture 5 software to control network
Tanveer Malik
 
DOC
Performance management strategy
katharine300
 
PDF
Network Monitoring System ppt.pdf
kristinatemen
 
Network monitoring Project Proposal.pptx
IT18GOWSIKKKUMARK202
 
network-management Web base.ppt
AssadLeo1
 
Identify and Resolve Ntwork Problems.pdf
Meresa Hiluf`
 
Computer Network Monitoring & Performance
Dmitry Ponomarenko
 
BSIT3CD_Continuation of Cyber incident response (1).pdf
StevenJoeBiago
 
Identify and resolve network problems
Abenezer Abiti
 
Chapter09
Muhammad Ahad
 
IRJET- Comparative Study on Network Monitoring Tools of Nagios Versus Hyp...
IRJET Journal
 
Importance of Network Performance Monitoring
cPacket Networks
 
Tune Up Your Network for the New Year
Savvius, Inc
 
Network monotoring
Programmer
 
networkmonitoringtools-200615094423.pptx
kelvinzallan5
 
Week10
Hayato
 
Netscan and Networx for Management Bandwidth and Traffic with Simple Routing
TELKOMNIKA JOURNAL
 
Network visibility and control using industry standard sFlow telemetry
pphaal
 
Network monitoring tools
QaswarBosan
 
Marvell Network Telemetry Solutions for Data Center and Enterprise Networks
Marvell
 
Lecture 5 software to control network
Tanveer Malik
 
Performance management strategy
katharine300
 
Network Monitoring System ppt.pdf
kristinatemen
 
Ad

Recently uploaded (20)

PPT
Confined Space.ppth. Bbbb. Bbbbbbbbbbbbbbbbbbbbbbbnnnjjj
eshaiqbal7
 
PPTX
Series.pptxvvggghgufifudududydydydudyxyxyx
jasperbernaldo3
 
PPTX
英国学位证(PSU毕业证书)普利茅斯大学毕业证书如何办理
Taqyea
 
PPTX
Flannel graphFlannel graphFlannel graphFlannel graphFlannel graph
shareesh25
 
PDF
Utility Software hshdgsvcjdgvbdvcfkcdgdc
imeetrinidadfuertesa
 
PPTX
一比一原版(UoB毕业证)布莱德福德大学毕业证如何办理
Taqyea
 
PPTX
西班牙维尔瓦大学电子版毕业证{UHU毕业完成信UHU水印成绩单}原版制作
Taqyea
 
PPT
(1) Chemotherapeutic drugs Antimicrobials.ppt
mkurdi133
 
PPTX
英国学位证(LTU毕业证书)利兹三一大学毕业证书如何办理
Taqyea
 
PPTX
ualities-of-Quantitative-Research-1.pptx
jamjamkyong
 
PPTX
哪里购买澳洲学历认证查询伊迪斯科文大学成绩单水印ECU录取通知书
Taqyea
 
PPT
Computer Hardware and Software Hw and SW .ppt
MuzaFar28
 
PDF
Development of Portable Spectometer For MIlk Qulaity analysis
ppr9495
 
PPTX
原版澳洲莫道克大学毕业证(MU毕业证书)如何办理
Taqyea
 
PPTX
Pranjal Accountancy hhw ppt.pptxbnhxududjylitzitzyoxtosoysitztd
nishantrathore042
 
PPT
it_14.ppt using atharva college of engineering
shkzishan810
 
PPT
COMBINATIONAL LOGIC DESIGN SADSADASDASDASDASDASDASDA
phmthai2300
 
PPTX
diagnosisinfpdpart1-200628063900 (1).pptx
JayeshTaneja4
 
PDF
Elevator Maintenance Checklist with eAuditor Audits & Inspections
eAuditor Audits & Inspections
 
PPTX
Dock Line Organization Made Easy – Discover AMARREX, the Mooring Line Holder ...
Seawatt
 
Confined Space.ppth. Bbbb. Bbbbbbbbbbbbbbbbbbbbbbbnnnjjj
eshaiqbal7
 
Series.pptxvvggghgufifudududydydydudyxyxyx
jasperbernaldo3
 
英国学位证(PSU毕业证书)普利茅斯大学毕业证书如何办理
Taqyea
 
Flannel graphFlannel graphFlannel graphFlannel graphFlannel graph
shareesh25
 
Utility Software hshdgsvcjdgvbdvcfkcdgdc
imeetrinidadfuertesa
 
一比一原版(UoB毕业证)布莱德福德大学毕业证如何办理
Taqyea
 
西班牙维尔瓦大学电子版毕业证{UHU毕业完成信UHU水印成绩单}原版制作
Taqyea
 
(1) Chemotherapeutic drugs Antimicrobials.ppt
mkurdi133
 
英国学位证(LTU毕业证书)利兹三一大学毕业证书如何办理
Taqyea
 
ualities-of-Quantitative-Research-1.pptx
jamjamkyong
 
哪里购买澳洲学历认证查询伊迪斯科文大学成绩单水印ECU录取通知书
Taqyea
 
Computer Hardware and Software Hw and SW .ppt
MuzaFar28
 
Development of Portable Spectometer For MIlk Qulaity analysis
ppr9495
 
原版澳洲莫道克大学毕业证(MU毕业证书)如何办理
Taqyea
 
Pranjal Accountancy hhw ppt.pptxbnhxududjylitzitzyoxtosoysitztd
nishantrathore042
 
it_14.ppt using atharva college of engineering
shkzishan810
 
COMBINATIONAL LOGIC DESIGN SADSADASDASDASDASDASDASDA
phmthai2300
 
diagnosisinfpdpart1-200628063900 (1).pptx
JayeshTaneja4
 
Elevator Maintenance Checklist with eAuditor Audits & Inspections
eAuditor Audits & Inspections
 
Dock Line Organization Made Easy – Discover AMARREX, the Mooring Line Holder ...
Seawatt
 
Ad

1. Network monitoring and measurement-2.ppt

  • 2. Definition • Network traffic measurement is the process of measuring the amount and type of traffic on a particular network. This is especially important with regard to effective bandwidth management. • Network monitoring describes the use of a system that constantly monitors a computer network for slow or failing systems and that notifies the network administrator in case of outages via email, pager or other alarms. It is a subset of the functions involved in network management.
  • 3. Motivation ★ Needs of service providers: ★Understand the behavior of their networks ★Provide fast, high-quality, reliable service to satisfy customers and thus reduce churn rate ★Plan for network deployment and expansion ★SLA monitoring, Network security ★Usage-based billing for network users (like telephone calls) ★Marketing using CRM data ★ Needs of Customers: ★Want to get their money’s worth ★Fast, reliable, high-quality, secure, virus-free Internet access
  • 4. Application • Network Problem Determination and Analysis • Traffic Report Generation • Intrusion & Hacking Attack (e.g., DoS, DDoS) Detection • Service Level Monitoring (SLM) • Network Planning • Usage-based Billing • Customer Relationship Management (CRM) • Marketing
  • 5. The General Traffic Flow Measurement Process Classification & Flow Recording Store (TCPdump) Observation Point PAYLOAD HEAD PAYLOAD HEAD PAYLOAD HEAD PAYLOAD HEAD Packet Capturing Filtering Display (Ethereal) Sampling Visualize (FlowScan) Analysis by applications (TE, attack detect., QoS monitoring, accounting, …) … other … packets Filtering Sampling flow records flow records packets packets flow records flow records
  • 6. Problems • Capturing Packets: ✴High-speed networks (Mbps ? Gbps ? Tbps) ✴High-volume traffic ✴Streaming media (Windows Media, Real Media, Quicktime) ✴P2P traffic ✴Network Security Attacks • Flow Generation & Storage: What packet information to save to perform various analysis? How to minimize storage requirements? • Analysis: How to analyze and generate data needed quickly? What kinds of info needs to be generated? -- Depends on applications
  • 7. Goals • Capture all packets • Generate flows • Store flows efficiently • Analyze data efficiently • Generate various reports or information that are suitable for various application areas Develop a flexible, scalable traffic monitoring and analysis system for high-speed, high-volume, rich media IP networks
  • 8. Network Monitoring Metrics • CAIDA Metrics Working Group (www.caida.org) ✴Latency ✴Packet Loss ✴Throughput ✴Link Utilization ✴Availability • IETF’s IP Performance Metrics (IPPM) Working Group ✴Connectivity (RFC 2687) ✴One-Way Delay (RFC 2679) ✴One-Way Packet Loss (RFC 2680) ✴Round Trip Delay (RFC 2681) ✴Delay Variation ✴Bulk transfer capacity
  • 9. One way loss RT loss One way delay RT delay Capacity Bandwidth Throughput Delay variance Network Monitoring Metrics Availability Connectivity Functionality Loss Delay Utilization
  • 10. • Availability: The percentage of a specified time interval during which the system was available for normal use. ✤Connectivity: the physical connectivity of network elements. ✤Functionality: whether the associated system works well or not. • Latency: The time taken for a packet to travel from a host to another. ✤Round Trip Delay = Forward transport delay + server delay + backward transport delay ✤Ping is still the most commonly used to measure latency. • Link Utilization over a specified interval is simply the throughput for the link expressed as a percentage of the access rate.
  • 11. Monitoring Method • Active Monitoring • Passive Monitoring
  • 12. Active Monitoring • Performed by sending test traffic into network • Generate test packets periodically or on-demand • Measure performance of test packets or responses • Take the statistics • Impose extra traffic on network and distort its behavior in the process • Test packet can be blocked by firewall or processed at low priority by routers • Mainly used to monitor network performance
  • 13. Passive Monitoring • Carried out by observing network traffic • Collect packets from a link or network flow from a router • Perform analysis on captured packets for various purposes • Network device performance degrades by mirroring or flow export • Used to perform various traffic usage/characterization analysis/intrusion detection
  • 14. Comparison of Monitoring Approaches Active monitoring Passive monitoring Configuration Multi-point Single or multi-point Data size Small Large Network overhead Additional traffic - Device overhead - No overhead if splitter is used Purpose Delay, packet loss, availability Throughput, traffic pattern, trend, & detection CPU Requirement Low to Moderate High
  • 15. Software in Network Monitoring and Management • EPM • The ping program • SNMP servers • IBM AURORA Network Performance Profiling System • Intellipool Network Monitor • Jumpnode • Microsoft Network Monitor 3 • MRTG • Nagios (formerly Netsaint) • Netdisco • NetQoS • NetXMS Scalable network and application monitoring system
  • 16. Software in Network Monitoring and Management • Opennms • PRTG • Pandora (Free Monitoring System) - Network and Application Monitoring System • PIKT • RANCID - monitors router/switch configuration changes • RRDtool • siNMs by Siemens • SysOrb Server & Network Monitoring System • Sentinet3 - Network and Systems Monitoring Appliance • ServersCheck Monitoring Software • Cacti network graphing solution • Zabbix - Network and Application Monitoring System • Zenoss - Network and Systems Monitoring Platform • Level Platforms - Software support for network monitoring