Collecting and Managing Network Traffic Data February 8, 2005
Essential (vague) Questions What –Conventionally: flow export (netflow, argus) –Other: IDS/IPS, event logs, application logs Why –Communicate Network Health – network provider –Manage ‘Network Performance’ – network admin –Study Network Behavior – researcher –Diagnose Network Misbehavior – diagnostician Help toward Gray’s Finger-pointing tool
Essential (vague) Questions Where – depends on the question and who’s asking –Manager/Diagnostician? Everywhere On campus: egress, core, borders Off campus –Shared networks – Abilene Observatory –Researcher? Anywhere (maybe) Whence – ah, that’s the trick –Long-term data needs
Today’s Panel Rick Summerhill, Internet2 –Director of Network Research, Architecture, and Technologies Jim Pepin, USC –CTO and Director of the Center for High Performance Computing and Communications Steve Worona, EDUCAUSE –Director of Policy and Networking Programs Mark Poepping, Carnegie Mellon –Head Architect and Director of …