Presentation is loading. Please wait.

Presentation is loading. Please wait.

ETRI meeting (Sep 14, 2004) -- Dongkee LEE 1 Internet Routing Anomaly Monitoring System Dongkee LEE.

Similar presentations


Presentation on theme: "ETRI meeting (Sep 14, 2004) -- Dongkee LEE 1 Internet Routing Anomaly Monitoring System Dongkee LEE."— Presentation transcript:

1 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr) 1 Internet Routing Anomaly Monitoring System Dongkee LEE

2 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)2Overview.  Internet Routing Anomaly Monitoring. (’04 8, 18 ~ )  Related works  System – the present position (’04 9, 14 - 16 )  Future works

3 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)3 IRAM – basic idea.  Internet Routing Anomaly Monitoring.

4 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)4 IRAM – goals.  Construct routes monitoring infrastructure.  Obtain real-time information about the global routing system.  Then, What can we do with this?  Survey on routing anomaly detection.  Other uses.  AS path visualization,  Map IP addresses to AS for topological studies.

5 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)5 Related works  University of Oregon – Route Views Project.  http://routeviews.org/ http://routeviews.org/  Routing information repository for …  Analysis of BGP routing table dynamics.  Work on routing table growth.  Analysis of geographic scope of routing announcements.

6 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)6 Related works  RIPE NCC – Routing Information Service.  http://www.ripe.net/ris/ http://www.ripe.net/ris/  Much more than a Looking glass.  Provide historical information about internet routing.  Collects information by using Remote Route Collectors at different locations around the world.  Integrate this information into a comprehensive view.

7 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)7 Related works  PacketDesign – Route Explorer  http://www.packetdesign.com/ http://www.packetdesign.com/  Extensive real-time and historical router event monitoring and analysis for troubleshooting networks using BGP connections.  Real-Time IP Network Visualization and Monitoring.  Detect, Analyze and Diagnose Layer 3 Problems.  User-Defined Alerts and Reports.  Scenario Planning and Impact Analysis.

8 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)8 Related works  PacketDesign – Route Explorer

9 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)9 Related works  PacketDesign -  http://www.packetdesign.com/flash/index.html http://www.packetdesign.com/flash/index.html

10 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)10 Related works  Jun Li, Routing forensics  Online BGP data analysis system that takes Route View data as the continuous input.  State machine - Detect suspicious routing information exchanged among BGP routers.

11 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)11 IRAM – On going works (1)  Design formal IRAM architecture.

12 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)12 IRAM – On going works (2)  EBGP peering with kaist-border router.

13 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)13 IRAM - On going works (3)  [~2004 09 15] Deploy bgpmon.kisti  More intelligent agent script for bgpmon. dump -> /yyyymm/UPDATES/, RIBS/ -> bzip archiving -> backup ?  Project web page.  http://an.kaist.ac.kr/~dklee/research/iram/ http://an.kaist.ac.kr/~dklee/research/iram/

14 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)14 IRAM - Future works.  Negotiate with other-net admins for EBGP peering.  What kind of views on data we need to provide?  It’s not a technical problem but a political problem!  Research on existing routing anomaly detection techniques.  Offline misconfigurations.  MOAS.  Cold potato.

15 ETRI meeting (Sep 14, 2004) -- Dongkee LEE (dklee@an.kaist.ac.kr)15  The END


Download ppt "ETRI meeting (Sep 14, 2004) -- Dongkee LEE 1 Internet Routing Anomaly Monitoring System Dongkee LEE."

Similar presentations


Ads by Google