An improved TCP protocol machine for flow analysis and network monitoring

被引:0
|
作者
Khosravi, H [1 ]
Fukushima, M
Goto, S
机构
[1] Waseda Univ, Dept Informat & Comp Sci, Tokyo 1698555, Japan
[2] KDDI R&D Labs Inc, Kamifukuoka, Saitama 3568502, Japan
关键词
finite state machine (FSM); TCP protocol machine; invalid flow; network congestion; intrusion detection;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In the Internet, flow analysis and network monitoring have been studied by various methods. Some methods try to make TCP (Transport Control Protocol) traces more readable by showing them graphically. Others such as MRTG, NetScope, and NetFlow read the traffic counters of the routers and record the data for traffic engineering. Even if all of the above methods are useful, they are made only to perform a single task. This paper describes an improved TCP Protocol Machine, a multipurpose tool that can be used for flow analysis, intrusion detection and link congestion monitoring. It is developed based on a finite state machine (automaton). The machine separates the flows into two main groups. If a flow can be mapped to a set of input symbols of the automaton, it is valid, otherwise it is invalid. It can be observed that intruders' attacks are easily detected by the use of the protocol machine. Also link congestion can be monitored, by measuring the percentage of valid flows to the total number of flows. We demonstrate the capability of this tool through measurement and working examples.
引用
收藏
页码:595 / 603
页数:9
相关论文
共 50 条
  • [1] Modified QUIC protocol for improved network performance and comparison with QUIC and TCP
    Kharat, Prashant
    Kulkarni, Muralidhar
    INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2019, 12 (01) : 35 - 43
  • [2] A new wireless network performance analysis of TCP protocol
    Li JingHua
    Li Yun
    Zhang Wen
    2012 2ND INTERNATIONAL CONFERENCE ON APPLIED ROBOTICS FOR THE POWER INDUSTRY (CARPI), 2012, : 1064 - 1066
  • [3] Electric device network monitoring system based on Modbus/TCP protocol and Web
    Chen, Bin
    Zhang, Bo
    An, Changsi
    Qiu, Dongyuan
    Yi Qi Yi Biao Xue Bao/Chinese Journal of Scientific Instrument, 2006, 27 (09): : 1062 - 1066
  • [4] Utilization of TCP/IP protocol for monitoring and control of technological processess via computer network
    Matysek, M.
    Sysel, M.
    Neumann, P.
    Annals of DAAAM for 2004 & Proceedings of the 15th International DAAAM Symposium: INTELLIGNET MANUFACTURING & AUTOMATION: GLOBALISATION - TECHNOLOGY - MEN - NATURE, 2004, : 281 - 282
  • [5] An Improved Congest Control Protocol Based on TCP Veno Protocol
    Zhang, Jianlin
    2013 IEEE 11TH INTERNATIONAL CONFERENCE ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING (DASC), 2013, : 653 - 656
  • [6] Research on TCP Protocol in Wireless Network and Network Simulation
    Lin, Fu
    Li, Xuefei
    Li, Wenhai
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 4492 - 4495
  • [7] Improved TCP Reno Protocol based on RTT
    Hou Weina
    Hu Feifei
    Gong Pu
    Li Yun
    Chen Qianbin
    2009 5TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-8, 2009, : 4077 - 4080
  • [8] Performance analysis of bulk flow TCP for routing in optical network
    Chettinad College of Engineerinmg and Technology, Department of Computer Science and Engineering, Puliyur C.F. -639 114, Karur District, Tamilnadu, India
    不详
    J Opt Commun, 2008, 2 (98-106): : 98 - 106
  • [9] LEARNING TCP PROTOCOL FUNDAMENTALS USING INNOVATIVE TCP FLOW TOOLBOX
    Van Hoecke, Sofie
    Petrov, Petar
    Vanacker, Tom
    Van de Walle, Rik
    ICERI2015: 8TH INTERNATIONAL CONFERENCE OF EDUCATION, RESEARCH AND INNOVATION, 2015, : 6731 - 6737
  • [10] Analysis of Socket Communication Technology Based on Machine Learning Algorithms Under TCP/IP Protocol in Network Virtual Laboratory System
    Si, Haiping
    Sun, Changxia
    Chen, Baogang
    Shi, Lei
    Qiao, Hongbo
    IEEE ACCESS, 2019, 7 : 80453 - 80464