html>
|
cflowd: Traffic Flow Analysis Tool |
CAIDA's cflowd is a flow analysis tool currently used for analyzing Cisco's netflow enabled switching method. Caida is releasing cflowd to enable ISPs to collect data for capacity planning and similar activities, and to involve ISPs and others in developing more advanced tools for graphing and displaying such information. Future plans call for cflowd to be available for other platforms such as Bay Networks, Juniper, and OC3mon data.
cflow is an important tool for ISPs for capacity planning, trend analysis and workload characterization, providing a means of analyzing traffic data by flow. Coral is a platform for non-intrusive, passive monitoring and analysis of Internet traffic. Full trace capture or traffic flow summaries are available at the FDDI through OC12 levels At the Internet Statistics and Metrics Analysis meeting, a recent CAIDA workshop, participants agreed that trend characterization such as that available through Coral and cflowd are important to capacity planning (of primary interest to ISPs) and to enhancing understanding of new Internet protocols/applications, i.e., streaming media (video & audio), voice over IP, DNS authentication, IPv6, etc.. Evaluating effects of non-conforming traffic for congestion and avoidance purposes are also important, e.g., TCP accelerators may require use of stocastic threat queuing techniques.
Other areas where cflowd may prove useful include usage tracking for Web hosting, accounting and billing, network planning and analysis, network monitoring, developing user profiles, data warehousing and mining, as well as security-related investigations.
Significant changes have been made in upgrading the cflowd software from version 1.3b2 (the last public release version) to version 2.0 (current release version). These changes include support for v1 and v5 Netflow Export versions, new tabular data, a system redesign including a new cflowdmux process that allows clients to connect to and receive raw flow streams, and a central collector that allows the user to archive time-series tabular data from multiple instances of cflowd.
There are several utilities included in the package which
may be used to examine data on the host(s) where cflowd is
running. More extensive analysis tools are planned which will be made available
to Caida members .
Mailing List
The cflowd mailing list is devoted to the discussion of cflowd.
To join the list send mail to
cflowd-request@caida.org
The address for the list is
cflowd@caida.org.
for more information:
info @ caida.org
last update:
this page:
http://www.caida.org/Tools/cflowd/