what really needed? operationally basic traffic characterization (how much) AS matrices traffic import/export routing/address space coverage security/vulnerability protection (DOS attack traces, filtering) more researchy interarrival time behavior protocol-relevant (dups, packet sizes)