Skip to main content

"Internet measurement: state of DeUnion"

Archived MagicPoint presentation slides, compiled into a single PDF document.

1999_soa9911.pdf (50 slides, 1.1 MB)

Slide text transcript

Slide 1: Internet measurement:

Internet measurement:

state of DeUnion


       scientific apparatus offers a window to knowledge, 
       but as they grow more elaborate, 
       scientists spend ever more time washing the windows. 
                                     -- Isaac Asimov 



kc claffy, UCSD/SDSC/CAIDA
kc@caida.org 
www.caida.org

Slide 2: abysmal but unsurprising

abysmal but unsurprising


little capacity to predict, depict, or even measure traffic behavior on current and advanced networks 

few tools to engineer/operate networks or identify traffic anomalies in real time

doesn't stop researchers from building junk

doesn't stop random users from doing random junk (no dearth of activity)

increasing risk to infrastructure

Slide 3: payoffs

payoffs


insights for vendors re next generation hw/sw requirement

calibration for users, e.g., monitoring service level agreements

diagnostic and planning tools for ISPs 

windows into the infrastructure for researchers

Slide 4: four areas of measurement

four areas of measurement


topology (mapping)

workload characterization (passive)

performance evaluation (active)

routing (dynamics)


  will show examples, priorities, obstacles

Slide 5: infrastructure-wide priorities

infrastructure-wide priorities 

dynamically discover/depict topology (& b/w)
correlate effects with BGP routing changes
correlate path performance with specific events
identify critical infrastructure within the Internet

Slide 6: skitter: infrastructure-wide measurements

skitter: infrastructure-wide measurements

17 monitors (inc. 1 root name server)
multiple lists 29k servers / 36k 2nd root server destinations
architecture:
     - parallel ICMP probes
     - 52-byte packets
     - kernel time stamping
     - ssh / Kerberos

Slide 7: skitter: colored by IP address

skitter: colored by IP address

Slide 8: skitter: colored by country

skitter: colored by country

Slide 9: skitter: colored by more countries

skitter: colored by more countries

Slide 10: skitter: AS interconnectivity

skitter: AS interconnectivity

Slide 11: skitter: cont'l connectivity

skitter: cont'l connectivity 
    
   www.caida.org/Tools/GeoPlot/
   [www.caida.org/Tools/NetGeo/]

Slide 12: GTrace: geographic traceroute

GTrace: geographic traceroute
  
   www.caida.org/Tools/GTrace/

Slide 13: GTrace: geographic traceroute

GTrace: geographic traceroute 
 
   www.caida.org/Tools/GTrace/

Slide 14: skitter: 3D hyperbolic

skitter: 3D hyperbolic 
 
BGP routing table data (connectivity among ASes)



    %%  

      %%layout: geographical
      %%layout: semi-geographical
     %%

Slide 15: mantra: analyzing multicast

mantra: analyzing multicast 

www.caida.org/Tools/Mantra

Slide 16: logical vs geographic topology

logical vs geographic topology

2-dimensional, hierarchical

geographic

Slide 17: semi-geographical (otter)

semi-geographical (otter) 

www.caida.org/Tools/Otter

Slide 18: topology: research priorities

topology:  research priorities 

visualization
latency
key routers/networks
AS granularity
geographic
integration w mgt tools

obstacles: 
     mapping IP addresses to
router
geography  
AS
service provider
country 	
anything...

    route changes faster than can measure

Slide 19: workload characterization

workload characterization


workload profiling (s/w & h/w design, architecture optimizing, capacity planning
security
performance analysis
delay, loss, jitter?
QOS assurance across ISPs
accounting/billing

tools: netramet, netflow, cflowd, coral
some suck less? ...evolution requires use

Slide 20

workload char.: protocol 

19 aug 99, ucsd-cerfnet

Slide 21

workload char.: protocol (proportion)

19 aug 99, ucsd-cerfnet

Slide 22: workload char: applications (ucsd-cerfnet)

workload char: applications (ucsd-cerfnet)

Slide 23: workload char.: mantra

workload char.: mantra

18 oct 99, fix-west.mbone.nasa.gov

Slide 24: workload: IP trade balance (pkts)

workload: IP trade balance (pkts)

12 march 98, 2 min sample, fixwest 
US still net exporter of IP pkts (w/2 exceptions)

Slide 25: packet sizes, 4/13/98 mci backbone

packet sizes, 4/13/98 mci backbone

half pkts 40 bytes, half payload in 1500 byte pkts

Slide 26: packet sizes by prefix length

packet sizes by prefix length

larger packets from shorter prefixes (why?)

Slide 27: favoritism/locality by AS

favoritism/locality by AS

80% of traffic from < 5% of ASes
60% of reachability from < 7% of ASes

Slide 28: flow length distribution, 4/13/98 mci backbone

flow length distribution, 4/13/98 mci backbone

heavy tail (quite truncated)
if you only learn about one distribution this quarter...
flow defn creates artifacts (100 bytes)

Slide 29: workload characterization: priorities

workload characterization: priorities

coral/ocXmons (OC3,12,48, gigE)

persistent, real-time, full-frame collection 

dynamic packet filtering triggered by attack precursors 

security policy 
compliance auditing (passive) 
enforcement (active) 

 obstacles
hardware expensive
privacy issues 
IPsec

Slide 30

workload char: working w/vendors


cflowd

www.caida.org/Tools/Cflowd 
primarily for capacity planning and trend analysis 
Cisco's netflow export  

AS-to-AS matrices 
net-to-net matrices 
port and protocol tables 
forward IP path 

measurement specifications to vendors

Slide 31: performance evaluation (active)

performance evaluation (active) 
 


network engineers to diagnose problems

ISPs & users to verify SLAs

designers of real-time apps to predict software HCI

Internet weather reports

Slide 32: perf. eval: skping (www.freebsd.org)

perf. eval: skping (www.freebsd.org)

Slide 33: perf.eval: routing (path change)

perf.eval: routing (path change)

Slide 34: perf.eval: sktrace (www.cnet.com)

perf.eval: sktrace (www.cnet.com)

Slide 35: performance eval.: priorities

performance eval.: priorities


definitions & metrics
bandwidth assessment techniques
correlation
across sources
with workload, routing data 
large scale deployment
user interface to measurements

obstacles
core infrastructural access
mathematicians needed
statisticians needed

Slide 36: routing dynamics

routing dynamics


15-year-old technology

admittedly seems like pretty good stuff

sausage/laws....

incredibly inefficient, incantation-driven

Slide 37: routing: example (instability)

routing: example (instability)


RTT data changes color if path changes
10 unique paths over 24 hour period
lots of jitter in data
unlikely to be intentional 
heavy tails predominate

Slide 38: routing: example (load balancing)

routing: example (load balancing)


RTT similar over predominantly two paths 
likely intentional load balancing

Slide 39: routing: sktrace (parc.xerox.com)

routing: sktrace (parc.xerox.com)

Slide 40: routing: research priorities

routing:  research priorities

effects of outages on surrouding ISPs
effects of topology changes on Internet performance
unintended consequences of new policies
MPLS
traffic engineering
dynamic detection/response to congestion & topology changes
identifying vulnerabilities created by dependencies on critical paths
utilization of address space
efficiency of routing table
asymmetric, instabilities in routing across providers
effects of unicast/multicast incongruity

Slide 41: routing: research obstacles

routing:  research obstacles 

canonical BGP (route table) data	(not so much anymore)

mapping IP address to anything 
   (we've been here before)

prudent security dictates making research difficult

Slide 42: now what?

now what?


`seamless': no such thing 
measurement tools/infrastructure 
well-considered
strategically deployed
collaboratively maintained 
more infrastructure-relevant research on resulting data
feedback into tool design 
correlation among data sources/types, simulation, visualization 
proactive participation
    top-down (app devel's scope constr.) 
    bottom-up (ISP cooperation)

Slide 43: skitter: macroscopic study

skitter: macroscopic study 

DNS f root server (pv's):  path wingspans 
www.caida.org/Tools/Skitter/

Slide 44: skitter: rtt vs hopcount (correlation?)

skitter: rtt vs hopcount (correlation?)

Slide 45: skitter: rtt distribution: tri-modal

skitter: rtt distribution: tri-modal

Slide 46: skitter: rtt vs longitude (light cone)

skitter: rtt vs longitude (light cone)

Slide 47: dispersion among ASes across paths

dispersion among ASes across paths

Slide 48: dispersion among ASes across paths (sdsc)

dispersion among ASes across paths (sdsc)

Slide 49: dispersion among countries across paths

dispersion among countries across paths

Slide 50: www.caida.org/Presentations/

www.caida.org/Presentations/

kc claffy
UCSD/SDSC/CAIDA
kc@caida.org
www.caida.org

Related Objects

See https://catalog.caida.org/media/1999_soa9911/ to explore catalog entries related to this document in the CAIDA Resource Catalog.