Changqing An

dblp:89/4268 · DBLP profile ↗
← Back
34ranked-venue papers
1as first author
15since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25 · 1 first-author · 9 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name Resolution
Fasheng Miao, Xiang Li 0108, Changqing An, Jilong Wang 0001
SP3
2026 Link Prediction-Based Measurement Strategy for Efficient Topology Completeness Improvements
abstract
The Autonomous System (AS) level topology observed from current measurement infrastructures is far from complete. Although Looking Glass (LG) vantage points (VPs) that support BGP route queries can provide valuable topology information, the query rate limitations of LG VPs imply that blindly using the VPs to conduct more measurements to improve the topology completeness is inefficient, if not infeasible. In this paper, we try to improve the efficiency by designing a link prediction based measurement strategy, whose basic idea is to first predict where unseen AS links are likely to be located and then use the prediction results to guide the measurements toward a more complete AS-level topology. We formulate the prediction of unseen AS links as a matrix completion problem and develop a side-information assisted learning-based matrix completion method. The method exploits a neural network and utilizes carefully chosen AS attributes based on our understanding on Internet peering practices, thereby learning more expressive latent vectors and achieving outstanding prediction performance in our scenario. We then develop a measurement strategy which takes the link prediction results as guidance to achieve efficient topology completeness improvements. The strategy leverages several heuristics to estimate the utilities of different measurements and takes a greedy algorithm to select the most valuable measurements. Experiments show that our link prediction method can achieve a high AUC (Area Under the Receiver Operating Characteristic Curve) of 0.834 and the link-guided measurement strategy can discover 1.82 times more unseen links than those discovered from non-guided measurement strategies with an equal number of measurements.
Shuying Zhuang, Hui Wang 0011, Jilong Wang 0001, Changqing An, Yuedong Xu 0001, Tianhao Wu 0010
IEEE Trans. Netw.4
2025 Poster: RMap: Uncovering Risky DNS Resolution Chains and Misconfigurations
abstract
In recent years, large-scale network outages caused by DNS misconfigurations have become increasingly common. The intricate inter-domain dependencies, along with emerging mechanisms (Such as DNSSEC, EDNS, and 0x20), have made DNS resolution increasingly complex and fault localization more challenging. We present RMap, a tool that rapidly probes all potential resolution chains of a domain, reveals its resolution dependency topology, and detects security risks. We experimentally demonstrate the effectiveness of RMap and its broad applicability. Our findings reveal that domain configurations in real-world environments remain concerning, with potential issues observed even in several well-known top-level domains. RMap is avaliable in https://github.com/ahlien/rmap.
Fasheng Miao, Shuying Zhuang, Xiang Li 0108, Changqing An, Deliang Chang, Baojun Liu 0002, Jia Zhang 0004, Jilong Wang 0001
IMC4
2025 Argus Lens: Innovating Internet Measurement Infrastructure via Relay Services
Changqing An, Jilong Wang 0001
Networking2
2025 Ares: Comprehensive Path Hijacking Detection via Routing Tree
Yinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang, Jilong Wang 0001, Congcong Miao
USENIX Security Symposium3
2024 Rumors Stop with the Wise: Unveiling Inbound SAV Deployment through Spoofed ICMP Messages
abstract
In the era of increasing network-based threats, particularly IP spoofing, Source Address Validation (SAV) is paramount for network security. The effective deployment of Inbound Source Address Validation (ISAV) is crucial yet often inadequate, posing significant risks to Internet infrastructure. This study presents ICMP_Sonar, a measurement system that deploys "rumors" -carefully crafted spoofed ICMP packets-to probe the network's defenses, revealing the "wise" networks with their robust ISAV implementations. ICMP_Sonar introduces two novel approaches that exploit the characteristics of ICMP unreachable messages and ICMP fragment needed messages, and exhibits the advantages of high coverage, fine granularity, low error rates, and the ability to measure in both IPv4 and IPv6. We also evaluate the applicability and security risks of ICMP error messages. Through large-scale measurements, ICMP_Sonar successfully covers 86M IPv4 hosts (0.8M IPv6 hosts), 3.5M IPv4 /24 subnets (24K IPv6 /40 subnets), and 59K IPv4 ASes (8.3K IPv6 ASes), surpassing the state-of-the-art dual-stack method's coverage by 16.2 (51.6), 2.9 (2.34), and 1.7 (1.7) times, respectively. The broad coverage across multiple granularities enables us to capture a more comprehensive and fine-grained view of ISAV deployment. Measurements show that while the percentage of ASes with no ISAV deployment is lower than previously identified, the percentage of ASes with partial ISAV deployment is much higher, indicating significant gaps in overall security. The analysis also reveals that ISAV deployment practices vary across different networks and between IPv4 and IPv6.
Shuaicong Yu, Shuying Zhuang, Changqing An, Jilong Wang 0001
IMC4
2024 ROV-GD: Improving the Measurement of ROV Deployment Using Graph Difference
abstract
BGP has been threatened by prefix hijacking attacks due to the lack of authentication mechanisms. In recent years, many ASes have begun to participate in RPKI deployment to improve Internet security jointly. Some researchers have studied how to measure the actual deployment of ROV globally, but such works suffer from the shortcomings of small measurement coverage and insufficient accuracy. Therefore, we propose RO-VGD, a ROV measurement method based on graph difference. We collect routing path data from the control plane and data plane. Then, we rely on prefix reachability and propagation edges for ROV inference. The results show that about half of the tested ASes have ROV filtering behaviors. In addition, our method can be extended to the ROV measurement of IXPs. Through validation and analysis, we prove that our method leads to convincing results and, at the same time, has a broader coverage and better applicability than other existing methods.
Han Zhang 0009, Changqing An, Jilong Wang 0001
ISCC4
2024 Investigate and Improve the Certificate Revocation in Web PKI
abstract
The validity and efficiency of certificate revocation in today's web Public Key Infrastructure (PKI) are consistently overlooked. In this paper, we analyse current certificate revocation schemes from the perspective of Certificate Authorities (CAs) and browsers. We find that the average size of CRL files collected from popular CAs can be as large as 2MB and the average response time of OCSP is around 430ms, which means that the time overhead brought by current certificate revocation schemes is not negligible. Moreover, browsers often fail to perform the revocation check correctly and allow websites to use revoked certificates, which can help attackers to launch man-in-the-middle attacks using fraudulent certificates.We also summarise existing problems and propose a novel certificate revocation scheme utilizing DNS resource records for efficient and privacy-preserving distribution. We have implemented a prototype to evaluate the performance of our scheme, and test results show that our scheme is time-efficient and able to withstand realistic workloads. We hope that our work can stimulate further discussion of the problems in Web PKI.
Changqing An, Zhiyan Zheng, Jilong Wang 0001
NOMS2
2023 Be Careful of Your Neighbors: Injected Sub-Prefix Hijacking Invisible to Public Monitors
abstract
Prefix hijackings have always been a significant security issue in BGP and have continued to occur in recent years. Detecting prefix hijackings is a vital part of defending against them. Most detection approaches mainly rely on the feed from the monitors of public route collector infrastructures. We propose an injected sub-prefix hijacking that utilizes the BGP communities attribute and AS path poisoning to control the propagation of invalid sub-prefix routes. This attack only pollutes neighboring ASes, thus guaranteeing the invisibility to monitors. Then the attacker can stealthily hijack traffic passing through the polluted ASes. Through extensive simulations, we show that this attack has an enormous impact and propose the crucial indicator affecting the attacker's capability. Finally, we demonstrate that existing defenses are difficult to handle this attack and then propose several defense strategies against it.
Han Zhang 0009, Changqing An, Jilong Wang 0001
ICC5
2023 Metis: Detecting Fake AS-PATHs Based on Link Prediction
abstract
BGP route hijacking is a critical threat to the Internet. Existing works on path hijacking detection firstly monitor the routes of the whole network and then directly trigger a suspicious alarm if the link has not been seen before. However, these naive approaches will cause false positive identification and introduce unnecessary verification overhead. In this work, we propose Metis, a matching-and-prediction system to filter out normal unseen links. We first use a matching method with three rules to find out suspicious links if there is an unseen AS. Otherwise, we propose using a neural network to make a prediction based on the AS information at each end of the link and further quantify the suspicion level. Our large-scale simulation results show that Metis can achieve precision and recall of over 80% for detecting fake AS-PATHs. Moreover, our deployment experiences show that compared to state-of-the-art system, Metis can save 80% overhead.
Chengwan Zhang, Congcong Miao, Changqing An, Anlun Hong, Ning Wang 0001, Jilong Wang 0001
ISCC3
2023 Evaluating and Improving Regional Network Robustness from an AS TOPO Perspective
abstract
Currently, regional networks are subject to various security attacks and threats, which can cause the network to fail. This paper borrows the quantitative ranking idea from the fields of statistics and proposes a ranking method for evaluating regional resilience. Large-scale simulated failure events based on probabilistic sampling is performed, and a significance tester that measures the impact of events from the overall level and variance aspect is also implemented. To improve a region’s robustness, this paper proposes a greedy algorithm to optimize the resilience of regions by adding key links among AS. This paper selects the AS topology of 50 countries/regions for research and ranking, evaluating the topology robustness from connectivity, user, and domain influence perspectives, clustering the results and get typical region types, and adding optimal links to improve the network resilience. Experimental results illustrate that the resilience of regional networks can be greatly improved by establishing a few new connections, which demonstrates the effectiveness of the optimization method.
Changqing An, Zhiyan Zheng, Zidong Pei, Jilong Wang 0001, Chalermpol Charnsripinyo
NOMS2
2023 Offloading Elastic Transfers to Opportunistic Vehicular Networks Based on Imperfect Trajectory Prediction
abstract
Due to the high cost of cellular networks, vehicle users would like to offload elastic traffic through vehicular networks as much as possible. This demand prompts researchers to consider how to make the vehicular network system achieve better performance for requests coming online, such as maximizing throughput. The traffic in vehicular networks is transferred through opportunistic contacts between vehicles and infrastructures. When making scheduling decisions, the scheduler must be aware of vehicles’ future trajectories. Vehicles’ future trajectories are usually predicted by trajectory prediction algorithms when users are unwilling to report their future trips. Unfortunately, no trajectory prediction algorithm can be completely accurate, and these inaccurate prediction results will degrade the throughput achieved by scheduling algorithms. In this paper, we focus on reducing the negative impact of inaccurate predictions. Specifically, we measure two data-driven trajectory prediction algorithms that have been widely used for trajectory predictions and understand the characteristics of the accuracy of predicted contacts. Based on the enlightenment from the measurement, we design a system, i.e., i-Offload, to offload elastic traffic under imperfect trajectory predictions. The experimental results show that our system has good throughput and high scheduling efficiency even under imperfect trajectory predictions. Compared with existing scheduling algorithms, our method improves the throughput by about one time.
Chao Xu 0015, Hui Wang 0011, Jilong Wang 0001, Yipeng Zhou, Yuedong Xu 0001, Di Wu 0001, Changqing An
IEEE/ACM Trans. Netw.8
2022 Phishing Detection Based on Multi-Feature Neural Network
abstract
Phishing detection methods are used to protect Internet users from leaking private information to phishing websites. However, the passive phishing detection method, which is widely used and based on blacklists, has limitations on timeliness and defense against zero-day phishing attacks and active phishing detection models with single-feature can be easily targeted by attackers. It is necessary to design and establish an active phishing detection model with high timeliness and strong adaptability. We propose a phishing detection method based on multi-feature extraction and deep learning technology. The model is constructed of a multilayer perceptron (MLP) for self-defined feature, a convolutional neural network (CNN) for image feature, a recurrent neural network (RNN) for text feature to extract feature vectors, and a classification network to fuse features and make the judgement. Our model’s accuracy achieves 0.9775 and recall reaches up to 0.9901. Experiment results of our model prove superior performance to those of other classification algorithms, demonstrating our model’s ability to deal with complex and changeable phishing detection tasks at this stage.
Shuaicong Yu, Changqing An, Tianshu Li, Jilong Wang 0001
IPCCC2
2022 Multi-hop Precision Time Protocol: an Internet Applicable Time Synchronization Scheme
abstract
Precise time synchronization is essential for 5G systems, data centers, industrial automation systems, military fields, and more. Although the precision of IEEE 1588 PTP can achieve sub-hundred-nanosecond accuracy, it works only when being deployed hop-by-hop within a LAN with limited range. Hop-by-hop deployment leads to high deployment costs and makes it inapplicable over the Internet. In this paper, we propose the multi-hop precision time protocol (M-PTP), a high-precision and low-cost time synchronization protocol, which does not require hop-by-hop deployment, and no special functions need to be added to the network relay devices such as routers and switches. M-PTP leverages two key ideas. First, to mitigate the "asymmetry in forward delay and reverse delay" problem, SVM-based delay estimation is used to calculate the distribution of positive and negative random delays, then L-estimator is leveraged to estimate the time offset. Second, based on time offset, M-PTP exploits loop effect optimization among nodes. We implemented the protocol and tested its performance on variance hops under different traffic conditions and CPU loads. The experimental results show that M-PTP can achieve a precision of 11.61ns at 5 hops, which is approximately 3 times the precision of HUYGENS and approximately 30 times the precision of PTP.
Kunling He, Changqing An, Hui Wang 0011, Tianshu Li, Linmei Zu
NOMS2
2022 Predicting Unseen Links Using Learning-based Matrix Completion
abstract
Researchers have noticed the AS-level Internet topology that can be observed from the current measurement infrastructure is far from complete, which means researchers have to deploy more measurement vantage points (VPs) and conduct measurements for more source/destination pairs to fully understand the whole Internet. Unfortunately, it is known that blindly deploying more points and conducting more measurements to achieve the goal is inefficient, if not infeasible. In this paper, we try to improve the efficiency by predicting where unseen AS links might be located from the observed AS paths to guide the measurements towards a more complete AS-level topology. We formulate the prediction of unseen links as a matrix completion problem. However, the traditional matrix completion methods have limited learning capacities and cannot deal with the complex constraints on the underlying topology. We develop a learning-based matrix completion method specifically for the unseen AS link prediction problem. The method exploits a neural network and utilizes side-information which is carefully chosen from AS attributes based on our understanding on Internet peering practices, therefore our method is able to learn more expressive latent vectors and achieves outstanding prediction performance in our scenario. Experiments performed on a real-world dataset show the prediction results can achieve a high AUC (Area Under the Receiver Operating Characteristic Curve) of 0.834.
Shuying Zhuang, Hui Wang 0011, Jilong Wang 0001, Changqing An, Yuedong Xu 0001, Tianhao Wu 0010
NOMS4
2019 Cost Efficient Internet Path Tracking Based on Routing Changes Prediction
abstract
Distributed network measurement is critical for various service. Researchers always would like to achieve measurement goals while minimizing the total overhead/cost of measurements. Therefore, the strategy of measurement, such as the selection of probes and their probing rates, is very important. In this paper, we focus on the measurement task of monitoring routing changes to destinations under study with measurement cost in consideration. We propose a decision algorithm to adaptively select vantage points and adjust detection frequency of each selected path. The decision is made based on a learning process aiming to characterize path characteristics and predict path changes. We further develop a tracking system, and the system allows researchers to specify their tradeoff preference between measurement efficiency and cost. We measured 100 paths under different scenarios. The results show that our system can allocate the detection resources more efficiently and detect the same number of path changes as the traditional system by using about 57% of the detection resources.
Changqing An
IPCCC2
2019 A survey on resource scheduling for data transfers in inter-datacenter WANs
Hui Wang 0011, Jilong Wang 0001, Changqing An, Qianli Zhang
Comput. Networks3
2019 An Adaptive Online Scheme for Scheduling and Resource Enforcement in Storm
abstract
As more and more applications need to analyze unbounded data streams in a real-time manner, data stream processing platforms, such as Storm, have drawn the attention of many researchers, especially the scheduling problem. However, there are still many challenges unnoticed or unsolved. In this paper, we propose and implement an adaptive online scheme to solve three important challenges of scheduling. First, how to make a scaling decision in a real-time manner to handle the fluctuant load without congestion? Second, how to minimize the number of affected workers during rescheduling while satisfying the resource demand of each instance? We also point out that the stateful instances should not be placed on the same worker with stateless instances. Third, currently, the application performance cannot be guaranteed because of resource contention even if the computation platform implements an optimal scheduling algorithm. In this paper, we realize resource isolation using Cgroup, and then the performance interference caused by resource contention is mitigated. We implement our scheduling scheme and plug it into Storm, and our experiments demonstrate in some respects our scheme achieves better performance than the state-of-the-art solutions.
Shengchao Liu, Jianping Weng, Hui Wang 0011, Changqing An, Yipeng Zhou, Jilong Wang 0001
IEEE/ACM Trans. Netw.4
2018 A study on geographic properties of internet routing
Hui Wang 0011, Changqing An
Comput. Networks2
2016 Characteristics analysis at prefix granularity: A case study in an IPv6 network
Fuliang Li, Jiahai Yang 0001, Xingwei Wang 0001, Tian Pan 0001, Changqing An
J. Netw. Comput. Appl.5
2014 A study of traffic from the perspective of a large pure IPv6 ISP
Fuliang Li, Changqing An, Jiahai Yang 0001, Hui Zhang 0052
Comput. Commun.2
2013 CSS-VM: A centralized and semi-automatic system for VLAN management
Fuliang Li, Jiahai Yang 0001, Changqing An
IM3
2013 IPv6 network topology discovery method based on novel graph mapping algorithms
abstract
As a crucial function of network management, network topology discovery provides a basis for lots of network analysis, such as network monitoring and performance management, etc. With the undergoing deployment of IPv6, the importance of precise topology discovery method in IPv6 networks becomes more and more evident. However, IPv6 network topology discovery faces new challenges due to different characteristics between IPv4 and IPv6, and the lack of well support of IPv6 related MIBs from device manufacturers in current state. At present, there are no well-accepted topology discovery methods for pure IPv6 networks with high accuracy, high coverage and less reliance on network configuration and device support. In this paper, we propose an IPv6 network topology discovery solution combining the advantages of two discovery methods, based on ICMP and routing protocol respectively. We model the mapping process of topology results from the two methods above into a graph mapping problem, which is the key point of the entire solution, and design novel mapping algorithms. We focus on the mapping coverage and accuracy and validate the mapping algorithms by large scale simulation. We also implement and test the proposed algorithms on the real network CERNET2. The experiments and simulation results verify the practicability and excellent performance of our solutions, with 100% discovery accuracy and over 99% discovery coverage while spending less time and producing lower overhead.
Jiahai Yang 0001, Changqing An, Fuliang Li
ISCC3
2012 Unravel the characteristics and development of current IPv6 network
abstract
In this paper, many aspects related to characteristics and development of IPv6 network are investigated. Additionally, in order to gain a deep view of IPv6 network, we correlate our system with a user authentication system, so we explore some meaningful user behaviors. According to the analysis, we obtain a comprehensive knowledge of current operating situation of IPv6 network which, we believe, can provide an experimental basis for IPv6 network operators and researchers.
Fuliang Li, Changqing An, Jiahai Yang 0001, Zejia Chen
LCN2
2011 Adaptive tuning of operation parameters for automatically learned filter table
abstract
Automatically learned filter table is used in many network security mechanisms to validate packets. Building filter item for each IP address in access networks can prevent IP spoofing at fine granularity but may consume large amount of filter table which is limited due to the expensive storage which is usually TCAM for high speed access. It is an urgent problem to use filter table effectively and keep network available. We analyze the change of filter table size and find that setting proper lifetime for filter item can significantly improve the utilization of filter table and avoid denial of service. In this paper, we take SAVI (source address validation improvement) switch as an example, and propose a dynamic adjustment method. It has two phases. Firstly it calculates out an optimal lifetime value for each switch based on one week user online logs, and then adjusts it dynamically to capture the bursts of filter table size. We deploy our prototype in a real campus network which has about 1000 SAVI switches providing network accessing service for nearly 20000 users. Based on the analysis of one month user online logs, we verify that our algorithm can reduce 92% of the duplicate confirming processes and guarantee the availability of network.
Changqing An, Jiahai Yang 0001
APNOMS2
2011 Investigating the efficiency of fine granularity source address validation in IPv6 networks
abstract
IPv6 protocol has been widely deployed in the world. As the IANA pool of IPv4 addresses has run out, IPv6 will become increasingly important. Although the IPv6 protocol stack presents considerable advantages compared with the IPv4 protocol stack, IP source address spoofing is still exploited in IPv6 to initiate malicious attacks. Some techniques are proposed and deployed to implement source address validation at fine granularity. In this paper, we investigate the efficiency of fine granularity IP source address validation, e.g. whether filtering technology is deployed to prevent hosts from using forged IP address. We develop a detection tool with controlled spoofing ability which can infer whether the function of filtering spoofing address packets is enabled. We run this tool in 12 famous universities in China and collect the testing data. We gather a total of 41373 probes from 324 clients, and each probe includes sending at least 5 packets with the same spoofing source address to the control server. Results reveal that, 77.02% of the spoofing probes are completely filtered, 0.29% of the spoofing probes are partly filtered and the rest spoofing probes are not filtered at all. Overall, this illustrates that techniques of source address validation have been widely deployed in campus networks. Our statistical results provide practical basis for the deployment and further development of source address validation protocols in IPv6 networks.
Fuliang Li, Changqing An, Jiahai Yang 0001
APNOMS2
2011 MIB design and application for source address validation improvement protocol
abstract
In this paper, we present SAVI-MIB, a management information base (MIB) designed to support configuration and monitoring of SAVI protocol which can provide fine granularity source address validation. Objects are defined to meet the detailed management requirement of local networks and accommodate different scenarios. SAVI-MIB is implemented in switches and deployed in some campus networks. Objects of SAVI-MIB are retrieved and used to help find configuration errors in SAVI deployment and profile behavior of end hosts. SAVI-MIB can also be used in parameter optimization, auto configuration, anomaly detection, etc.
Changqing An, Hui Wang 0011, Jiahai Yang 0001
ISCC1
2011 A study of traffic, user behavior and pricing policies in a large campus network
Hui Wang 0011, Changqing An, Jiahai Yang 0001
Comput. Commun.2
2011 A study on key strategies in P2P file sharing systems and ISPs' P2P traffic management
Hui Wang 0011, Chungang Wang, Jiahai Yang 0001, Changqing An
Peer-to-Peer Netw. Appl.4
2009 Towards Next Generation Internet Management: CNGI-CERNET2 Experiences
Jiahai Yang 0001, Hui Zhang 0052, Jinxiang Zhang, Changqing An
J. Comput. Sci. Technol.4
2008 Understanding IPv6 Usage: Communities and Behaviors
Shaojun Huang, Changqing An, Hui Wang 0011, Jiahai Yang 0001
APNOMS2
2006 Scalable Double Filter Structure for Port Scan Detection
abstract
Port scan detection is very important to predict network intrusions and prevent viruses from spreading. Many networks deploy Network Intrusion Detection Systems (NIDS) to detect port scans in real-time. However, most NIDS are perflow based. They are not scalable on high speed links since it is infeasible to maintain the states of numerous flows. In this paper, we propose a scalable scheme for real-time port scan detection without keeping any per-flow state. We use a double-filter structure to find outpairs which connect to more than Npairs in T time. The experimental results on real network traces show that our scheme can find out those over-thresholdpairs with high accuracy. It is easy to scale our scheme to high speed environments due to its little memory consumption and fast processing pipeline.
Shijin Kong, Xiaoxin Shao, Changqing An, Xing Li 0001
ICC4
2006 SANTT: Sharing Anonymized Network Traffic Traces among Researchers
abstract
Current Internet research suffers from limited information available from public network traffic traces due to the privacy concern of ISP and lack of effective trace distribution systems. In this paper, we present our SANTT (sharing anonymized network traces) system to share valuable network traffic traces safely and widely. SANTT employs a novel prefix-preserving anonymization method to sanitize privacy information in packets and takes advantage of specific high-speed traffic capturing hardware. After removing privacy information, SANTT distributes the traces by multicast, which makes it easy for researchers to access. The experimental results show that SANTT implemented on IXP2400 platform can process the fastest traffic rate (1,1953,125 PPS) offered by Gigabit links with high accuracy and stability
Xiaoxin Shao, Qianli Zhang, Shijin Kong, Changqing An, Xing Li 0001
NOMS5
2005 Traffic Measurement and Analysis of TUNET
abstract
Traffic measurement and analysis, as one of the important methods of understanding and characterizing network, can provide significant support for network management. After a brief introduction of a novel NP (network processor)-based architecture of traffic measurement, the paper presents the detailed analysis results of the traffic collected from the gigabit link connecting Tsinghua University campus network (in short, TUNET) to its upstream ISP, China Education and Research NETwork (in short, CERNET). Then, the paper comprehensively analyzes the traffic from multi-dimension viewpoints, including temporal distribution, packet length distribution, port-based distribution, protocol-based distribution, and TopN statistics. Such analysis not only provides support for the study of user behavior, but also enriches traffic measurement technology
Jun Zhang 0004, Jiahai Yang 0001, Changqing An, Jilong Wang 0001
CW3