Return to search

Evaluation of packet capturing systems for passive monitoring

Computer Network monitoring is a part of network managements. There are active and passive monitoring techniques. Evaluation and comparison of both techniques have been done in previous works. Only one previous work was focusing on passive monitoring such as TAP and Port mirroring, specifically on Port-mirroring technique. This motivated us to repeat the experiment, which was primary done by J. Zhiang and A. Moore, and evaluate existing passive monitoring techniques TAP and Port- mirroring in more detail. We have done a qualitative experiment in the laboratory and we noted that Port-mirror used a significant amount of the Central Processor Unit (CPU) during the process. White papers introduced Port-mirroring as a passive network monitoring method without affecting the performance, but our results showed it does have an effect. Also, can confirm, that Port-mirroring was reordering packets, had process delay and in case of congestion it dropped packets. TAP operated without packet loss. The packets sequence does not change, so saves operating time and is fully passive. Captured packets contain such information as the source address, destination address, and different protocols information. It was also possible to get the information about connected resources.

Identiferoai:union.ndltd.org:UPSALLA1/oai:DiVA.org:hh-23451
Date January 2013
CreatorsMickevičiūtė, Asta, khan, Hasan
PublisherHögskolan i Halmstad, Sektionen för Informationsvetenskap, Data– och Elektroteknik (IDE), Högskolan i Halmstad, Sektionen för Informationsvetenskap, Data– och Elektroteknik (IDE)
Source SetsDiVA Archive at Upsalla University
LanguageEnglish
Detected LanguageEnglish
TypeStudent thesis, info:eu-repo/semantics/bachelorThesis, text
Formatapplication/pdf
Rightsinfo:eu-repo/semantics/openAccess

Page generated in 0.0017 seconds