- 1、本文档共10页,可阅读全部内容。
- 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
- 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
SHARKFEST 08 Foothill College March 31 - April 2, 2008.ppt
SHARKFEST 08 | Foothill College | March 31 - April 2, 2008 Protocol Analysis in a Complex Enterprise April 2nd, 2008 Hansang Bae Senior VP | Citigroup SHARKFEST 08 Foothill College March 31 - April 2, 2008 SHARKFEST 08 | Foothill College | March 31 - April 2, 2008 Challenges: As it turns out, size does matter! Citi’s branch network spans 5,000+ locations in the US Citi’s network infrastructure includes 30,000+ devices 300,000 users located in over 100 countries. Compliance/Security Quagmire It’s for your own protection, or so I’m told! Doing a full packet capture is difficult Wireshark is the only approved protocol analyzer at Citi. It dislodged past market leaders. Challenges (con’t): Capturing and Analyzing: Two pieces to the same puzzle Enormous amounts PCAP data are involved. In most cases, header analysis is adequate. Wireshark/WinPCAP is not well suited for this much volume Citi uses a commercial product for packet capturing. Working with the vendor, it took over three years of development before it was deemed “Citi-ready” Example One: Path MTU Infrastructure size makes it interesting. Very difficult problem without a proper protocol analyzer Example One: (Con’t) In depth understanding of routers and protocols were required. Usenet to the rescue! ICMP and IP.ADDR filters were key! So which side am I on in the “religious debate” about whether ICMP messages should be included in the “ip.addr” display filter? ..\..\..\Traces\Consumer\CBNA\ICMPRateLimit.pcap In retrospect, it was an easy problem to solve. Yet the sheer size made it difficult to spot. Example Two: Clock Drift MarketData driven business complains of extreme delays from UK to US. At first glance, application logs seem to confirm delays in the 200+ms delays. RTT is 70ms. Because it’s easy, let’s blame the firewall and the network! SLA tracking and further investigation of routers/switches gets us nowhere with problem resolution. Our analysis shows that something i
您可能关注的文档
- Metaphysical Poetry.ppt
- mián.ppt
- Microsoft.com.ppt
- Mixed culture biotechnology for bioenergy production.ppt
- MKT201 – Buyer Behavior.ppt
- Module 2 My New Teachers.ppt
- Module 3 On the radio.ppt
- Module 4Unit 1 Advertising.ppt
- Module 5 Unit 3 Science versus nature.ppt
- Module 5-6复习提纲.ppt
- 2025至2030年中国控制脂肪及肌肉食品市场分析及竞争策略研究报告.docx
- 2025至2030年中国日式风镜市场分析及竞争策略研究报告.docx
- 2025至2030年中国极细微粒钨钢多刃端铣刀市场分析及竞争策略研究报告.docx
- 2025至2030年中国柔性石墨增强复合板市场分析及竞争策略研究报告.docx
- 2025至2030年中国桑拿发汗片市场分析及竞争策略研究报告.docx
- 2025至2030年中国棕刚玉P砂市场分析及竞争策略研究报告.docx
- 2025至2030年中国橡胶抛光盘市场分析及竞争策略研究报告.docx
- 2025至2030年中国正面锁市场分析及竞争策略研究报告.docx
- 2025至2030年中国复合式斜断锯市场分析及竞争策略研究报告.docx
- 2025至2030年中国柜台式展示架市场分析及竞争策略研究报告.docx
文档评论(0)