ETRI meeting (Sep 14, 2004) -- Dongkee LEE 1 Internet Routing Anomaly Monitoring System Dongkee LEE
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Internet Routing Anomaly Monitoring. (’04 8, 18 ~ ) Related works System – the present position (’04 9, ) Future works
ETRI meeting (Sep 14, 2004) -- Dongkee LEE IRAM – basic idea. Internet Routing Anomaly Monitoring.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE IRAM – goals. Construct routes monitoring infrastructure. Obtain real-time information about the global routing system. Then, What can we do with this? Survey on routing anomaly detection. Other uses. AS path visualization, Map IP addresses to AS for topological studies.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Related works University of Oregon – Route Views Project. Routing information repository for … Analysis of BGP routing table dynamics. Work on routing table growth. Analysis of geographic scope of routing announcements.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Related works RIPE NCC – Routing Information Service. Much more than a Looking glass. Provide historical information about internet routing. Collects information by using Remote Route Collectors at different locations around the world. Integrate this information into a comprehensive view.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Related works PacketDesign – Route Explorer Extensive real-time and historical router event monitoring and analysis for troubleshooting networks using BGP connections. Real-Time IP Network Visualization and Monitoring. Detect, Analyze and Diagnose Layer 3 Problems. User-Defined Alerts and Reports. Scenario Planning and Impact Analysis.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Related works PacketDesign – Route Explorer
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Related works PacketDesign -
ETRI meeting (Sep 14, 2004) -- Dongkee LEE Related works Jun Li, Routing forensics Online BGP data analysis system that takes Route View data as the continuous input. State machine - Detect suspicious routing information exchanged among BGP routers.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE IRAM – On going works (1) Design formal IRAM architecture.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE IRAM – On going works (2) EBGP peering with kaist-border router.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE IRAM - On going works (3) [~ ] Deploy bgpmon.kisti More intelligent agent script for bgpmon. dump -> /yyyymm/UPDATES/, RIBS/ -> bzip archiving -> backup ? Project web page.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE IRAM - Future works. Negotiate with other-net admins for EBGP peering. What kind of views on data we need to provide? It’s not a technical problem but a political problem! Research on existing routing anomaly detection techniques. Offline misconfigurations. MOAS. Cold potato.
ETRI meeting (Sep 14, 2004) -- Dongkee LEE The END