节点文献
基于应用层和传输层的网络测量分析研究
Internet Measurement and Traffic Characterization Based on Application Layer and Transport Layer
【作者】 张敏;
【导师】 陈常嘉;
【作者基本信息】 北京交通大学 , 通信与信息系统, 2012, 博士
【摘要】 随着互联网规模的不断扩张和网络应用的极大丰富,准确地认识和评估网络本身及网络应用的特征,有利于调整和改进现有的互联网基础软硬件设施,继而保障互联网健康持续的发展。作为当前观测、理解和评估互联网这个复杂巨系统的重要手段,网络测量研究正面临着诸多严峻的挑战。目前网络测量侧重于揭示网络本身或网络应用瞬时或短期的行为特征,而忽视了针对网络特征演变过程的刻画。有效地度量并描述互联网内涵不断变化演进的过程,有利于评估新技术或新协议对系统的影响,准确地预测网络发展趋势,是非常具有研究价值而鲜有报道的重要问题之一;其次,单一的小规模测量难以应对网络及其应用复杂度的提高和规模的扩大。如何针对具体的测量目的来设计综合性的测量方案?如何扩大测量规模?是测量方法设计上需要解决的关键问题;第三,现有的大量实际的网络测量工作从孤立数据集入手,刻画分析网络的相关特性,缺乏融合多组数据集的研究分析;第四,当前网络测量研究结论的呈现较为单一和抽象,人们无法直观地了解互联网,同时也阻碍了研究人员之间的交流互动。如何借助于图形化手段,全面生动地表达测量结果是一个值得讨论的问题;此外,网络测量关键技术的探讨和理论性研究相对滞后,有待于深入的研究和建设。针对上述网络测量现存的主要问题,本文通过形式多样的测量实践,从互联网的应用层和传输层角度展开研究。论文的主要内容和创新如下:1)网络应用特征的持续性刻画和测量手段单一、规模较小是网络测量领域亟待解决的两大问题。本文针对互联网的支撑型基础应用——DNS根服务器系统和热门的P2P代表性应用·——EDonkey、迅雷,展开测量研究。通过针对散布在全球各地的分布式DNS根服务器系统的大规模长期协同测量,分析了四年来DNS根服务器系统基本特征的演变过程,评估了新技术IPv6和DNSSec (DNS Security Extensions, DNS安全扩展机制)在DNS根服务器系统中的实际部署和运行状态,填补了网络测量领域尚未针对该系统的大规模长期测量研究的空白。数据分析结果表明四年以来DNS根服务器在查询污染,工作负载,查询地理位置分布等基本特性表现出较强的一致性;DNSSec并未获得广泛的用户支持,有待于进一步的推广和部署。另一方面,针对P2P热点应用,综合考虑主被动测量的弊端和优势,本文设计了不同的测量方案,分别研究了EDonkey网络中假服务器行为特征;揭示了迅雷系统的基本构架和客户端的一般工作流程,验证并评估了迅雷系统的“盗链”行为。在揭示相关应用特征的同时,对网络应用新协议设计、网络流量管理等具有一定的实际意义。2)针对融合多组数据集的分析研究较少的现状,本文一方面从多组骨干网数据集入手,揭示了UDP流特征随P2P应用兴起所发生的变化;另一方面,从传输层和应用层两个角度,分析比较了国内外校园网数据集的基本特征,并且评估了基于常见流量特征的分类模型在不同数据集上的效用。实验结果表明Sizes类(分组包大小)特征的分类效果明显优于其他流特征。3)针对网络数据可视化较为单一抽象的现状,设计了基于AJAX技术的数据可视化交互式系统平台,不仅实现了全面的数据分析结论呈现和比较,而且最大限度地支持用户与数据集的交互,有利于研究人员之间的交互,为数据可视化提供了新的思路。4)针对网络测量关键技术和问题研究的相对滞后,围绕大规模协同测量和多组数据集分析两个方面,探讨了实际测量分析中测量探针位置选择、数据集规范、私隐信息去除、数据集共享等一系列关键性技术,对测量分析平台的建设和网络测量分析方法的研究具有一定的参考价值。
【Abstract】 The Internet continually evolves in scope and complexity, much faster than our ability of observing and characterizing Internet, even predicting its development. As a major and critical means of understanding Internet, the study of Internet measurement is challenged.Firstly, the state of the art in Internet measurement still lacks long-term measurement and charactization studies, and these studies are important for revealing the evolvement of Internet traffic or network applications which can be used to evaluate the impact of new technologies or protocols and predict the network development; thus it is an important issue valuable for researching. Secondly, simple and small-scale measurement is hard to handle the growing complexity and scope of Internet. How can the comprehensive scheme be designed for concrete measurement purposes? How can the measurement scale be enlarged? They are both crucial issues in measurement methodology. Thirdly, the variety of datasets used does not allow systematic comparison of methods, and their poor comparability of results is further amplified by the lack of standardized measures and classifications goals. The forth, the research conclusions are presented singly and abstractly which hinders the communications among researchers and make difficulties for people to under Internet intuitively. How can a measurement conclusion be expressed lively? It is an issue worthy of discussion. In addition, the theoretical study on Internet measurement is backward currently.Towards the problems mentioned above, this paper has conducted various measurement and analysis studies, focusing on traffic characterization and traffic classification. The main research and innovation of this thesis are as follows:1) Considering the lack of network evolvement description and the oneness and small scale of measurement means, we conduct several measurements and analysis on Internet applications. By carrying out four annual large-scale data collection events over the top layer of the DNS hierarchy, this long-term study of the DNS root system shows some trends, including the consistency of query types distribution, workload, misconfigured pollution, etc. We also present new results on security-related attributes of the client population:a short-term measure to improve DNS security, and a surprising decreasing trend in the fraction of DNSSec-capable clients. Our insights on IPv6data are limited to the nodes that collected IPv6traffic, which does show growth. On the other hand, this thesis also conducted measurements on two popular P2P applications, for understanding the behavior of fake servers in eDonkey system, and exploring Xunlei’s architecture and characterizing its downloading process, even analyzing bandwidth theft in Xunlei.2) Considering the lack of the study of multiple datasets, this thesis characterizes the features of the UDP flow along with the recent rising of P2P file-sharing applications. Moreover, an across-study on two campus traces is done both from the transport layer and application layer. We also evaluate the features on flow level over different datasets. Our experiment results show that the packet size is a robust feature for applying the traffic classification model.3) In the view of the simple and dull way to present datasets, this thesis has designed and deployed an interactive data visualization platform by AJAX, which not only presents the analysis results comprehensively, but also supports the interactive between users and datasets flexible.4) Considering the backward of Internet measurement theoretical study, this thesis has presented a structured taxonomy of traffic classification papers and their datasets, for revealing issues and challenges in traffic classification. On the other hand, based on our measurement and analysis studies, the discussion of methods and technique is open for conducting global trace collection experiments and utilizing collected various datasets, in order to contribute some insights to the establishment of the measurement infrastructure over our campus.
【Key words】 Network Measurement; Traffic Classification; Peer-to-Peer; DNS RootSystem;