next up previous contents
Next: Topology Up: Analysis Previous: MAC Addresses   Contents


Subnets

After spending a few hours issuing queries against tcpdump and trying to look at different statistics of the data, we decided to develop a parser that would take tcpdump output and put it into a MySQL[17] database. The parser can be found on the AfterGlow[14] Web page along with all the scripts to generate the graphs in this paper.

To further understand the environment we are dealing with, it would be helpful to know what subnets are behind all the three devices. Figure 2.2 shows a communication graph. All IP addresses are aggregated into A classes. This gives us a first and rough understanding of the address spaces and the topology2.4.

Figure 2.2: Topology showing IP subnets (circles, summarized in A classes) and their border devices (boxes). The arrows indicate the direction of traffic from the device. An arrow leaving a device (box) indicates that traffic targeted this subnet. An arrow entering a device (box) indicates traffic originating from this subnet (circle).
Image topology

Looking at Figure 2.22.5, we see a few interesting things:


next up previous contents
Next: Topology Up: Analysis Previous: MAC Addresses   Contents
Raffy 2004-12-20