Technological advances and the rapid evolution of the Internet and computer networks,including enterprise networks, make it necessary to implement a network management strategy in order to optimize the use of resources, plan infrastructure sizing and Support quality-of-service systems and security mechanisms. To achieve this objective, it is essential to know the traffic conveying through the network. However, such evolution has led to an increase in the volume of traffic and consequently the amount of data to be explored.
Metrology and traditional tools such as the analysis of log files, tables or tools that list packets exchanged between machines do not meet new requirements on data mining and do not allow users to derive relevant information from a huge raw dataset for decision-making purposes.
In this thesis, we design and develop a visualization framework that explores network data or IP traffic to monitor various aspects of a network. This information used in multidimensional data in large quantity so as to report to the user the state of the network to monitor in real time. To achieve this, we have investigated a set of methodological approaches to visualize network data, which is a data processing process aiming at graphically present useful information in simple and expressive graphs.
The research framework proposed in this thesis provides three additional levels of information. The first level overviews the network through analytics of traffic volumes, the number of connections and the distribution of packet size in real time. The second analyzes traffic at the transport level mapping internal and external flows between the different machines, and analyzing port-based traffic to detect malicious flows. A third level allows identifying and classifying applications in real time using machine learning. Data sampling methods were used to reduce the processing cost ensure real-time analysis.
A functional test was carried out validating the features offered by the proposed framework. In the same way, a set of performance metrics were examined and the results show that our solution is more efficient in terms of memory rates and CPU used in comparison with a typical traffic visualization application called TNV. In addition, the proposed visualization framework makes it possible to report network states in real time, which enables quality of service and security.
| Date | 15 Jun 2017 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Mohamed Cheriet (Supervisor) |
|---|
Elbaham, M. (Author),
Cheriet (Supervisor),
15 Jun 2017Student thesis: Master's thesis › Master in Engineering: Engineering