High Speed Network Monitoring and Analyis




  • collaboration with TU Munich
  • supported by EU project DIADEM
  • supported by BMBF project 3GET
  • supported by Audi AG
  • supported by BSI project monk-it
  • supported by DFG travel grants



The aim of this project is to build an architecture, methods, and tools for distributed network analysis. The HISTORY analysis environment makes it possible to collect information about network traffic and its behavior in distributed high-speed network environments. The employment of standardized protocols (IETF IPFIX, PSAMP, and NSIS) results in an extensible architecture. A main objective is to develop methodologies for handling high amounts of statistics and packet data even with cheap low-end components. A second goal is to search for optimized methodologies for attack and intrusion detection and traceback mechanisms. The emphasis lies on probabilistic methods. Additionally, the distributed analysis of the data in autonomously working simple entities is studied. Visualization techniques and anonymization methods round off the big picture of a visionary environment for all network monitoring and analyzing challenges. All the developed tools will be available under an open source license.

Research Goals and Objectives

  • Cooperative autonomous entities with distributed functioning
  • Emergent behavior through adaptive self-organization
  • Operation in high-speed networks while utilizing standard PC components
  • Wide application range from accounting and charging up to traffic engineering, intrusion detection, and traceback
  • Anonymization techniques for wide applicability

Research Areas

  • Network Monitoring
    netflow accounting and packet sampling
  • Traffic Analysis
    accounting, attack and intrusion detection, and traceback
  • Experimental Environment
    traffic generation, simulation, and automated testbed setup

Selected Publications

