Re: TCP flags packet counting

Masoud Sadri <[email protected]> Mon, 10 Dec 2018 21:27:09 +0330
Newsgroups gmane.network.argus
Message-ID <CAAyATt-kLEonY_n6O+0LJKRf9SmTZeMLryJdtHzYZMSJUeBUPA@mail.gmail.com>
--0000000000005c0eab057caec26c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks for your reply.
My thesis is about finding the anomaly in network flows. I used Johan Mazel
thesis[1] as the base of my work. As you can see in section 3.1.2,
"Multi-resolution Flow Aggregation"; he aggregated network flows and
extracted nine features from them. Two of them(nRST/nPkts and nSYN/nPkts)
depend on TCP flags counter field.

Masoud

[1] https://tel.archives-ouvertes.fr/tel-00667654/document

On Sun, Dec 9, 2018 at 5:36 PM <[email protected]> wrote:

> Hey Masoud,
> We don=E2=80=99t track the number of packet types in a TCP connection, no=
t
> something that has come up in a few decades.  It would be easy to do, and
> would involve extending the TCP DSR to add counters for each flag type, a=
nd
> of course all their combinations.  But as I mentioned, no one has been
> looking for those metrics.
>
> Can you tell us why this is important to your thesis ???  Are you doing
> something for security or operations ???
>
> Carter
>
> On Dec 8, 2018, at 3:01 PM, Masoud Sadri <[email protected]> wrote:
>
> Hi,
> In addition of total packets in each record I need to know the number of
> syn,ack,fin,rst,urg,psh,cwr,ece packets separably.
> Could you help me, please?
>
>
> <https://www.avast.com/sig-email?utm_medium=3Demail&utm_source=3Dlink&utm=
_campaign=3Dsig-email&utm_content=3Dwebmail&utm_term=3Dicon> Virus-free.
> www.avast.com
> <https://www.avast.com/sig-email?utm_medium=3Demail&utm_source=3Dlink&utm=
_campaign=3Dsig-email&utm_content=3Dwebmail&utm_term=3Dlink>
>
>
>

--0000000000005c0eab057caec26c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div>Thanks for your rep=
ly.</div><div>My thesis is about finding the anomaly in network flows. I us=
ed Johan Mazel thesis[1] as the base of my work. As you can see in section =
3.1.2, &quot;Multi-resolution Flow Aggregation&quot;; he aggregated network=
 flows and extracted nine features from them. Two of them(nRST/nPkts

 and nSYN/nPkts) depend on TCP flags counter field.</div><div><br></div><di=
v>Masoud</div><div><br></div><div>[1]=C2=A0<a href=3D"https://tel.archives-=
ouvertes.fr/tel-00667654/document" target=3D"_blank">https://tel.archives-o=
uvertes.fr/tel-00667654/document</a>=C2=A0=C2=A0<br></div></div></div></div=
><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Sun, Dec 9, 2018 at 5:3=
6 PM &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">carter@qos=
ient.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D=
"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le=
ft:1ex"><div>Hey Masoud,<div>We don=E2=80=99t track the number of packet ty=
pes in a TCP connection, not something that has come up in a few decades.=
=C2=A0 It would be easy to do, and would involve extending the TCP DSR to a=
dd counters for each flag type, and of course all their combinations.=C2=A0=
 But as I mentioned, no one has been looking for those metrics. =C2=A0</div=
><div><br></div><div>Can you tell us why this is important to your thesis ?=
??=C2=A0 Are you doing something for security or operations ???</div><div><=
br><div>Carter =C2=A0<div><br><blockquote type=3D"cite"><div>On Dec 8, 2018=
, at 3:01 PM, Masoud Sadri &lt;<a href=3D"mailto:[email protected]" tar=
get=3D"_blank">[email protected]</a>&gt; wrote:</div><br class=3D"gmail=
-m_8033978383335197755gmail-m_3971965068078662434Apple-interchange-newline"=
><div><div dir=3D"ltr"><div>Hi,</div><div class=3D"gmail-m_8033978383335197=
755gmail-m_3971965068078662434fonttools-rtl"><div>In addition of total pack=
ets in each record I need to know the number of syn,ack,fin,rst,urg,psh,cwr=
,ece packets separably.=C2=A0</div><div>Could you help me, please?</div></d=
iv></div><div id=3D"gmail-m_8033978383335197755gmail-m_3971965068078662434D=
AB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br>
<table style=3D"border-top:1px solid rgb(211,212,222)">
	<tbody><tr>
        <td style=3D"width:55px;padding-top:13px"><a href=3D"https://www.av=
ast.com/sig-email?utm_medium=3Demail&amp;utm_source=3Dlink&amp;utm_campaign=
=3Dsig-email&amp;utm_content=3Dwebmail&amp;utm_term=3Dicon" target=3D"_blan=
k"><img alt=3D"" width=3D"46" height=3D"29" style=3D"width: 46px; height: 2=
9px;"></a></td>
		<td style=3D"width:470px;padding-top:12px;color:rgb(65,66,78);font-size:1=
3px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free. <a=
 href=3D"https://www.avast.com/sig-email?utm_medium=3Demail&amp;utm_source=
=3Dlink&amp;utm_campaign=3Dsig-email&amp;utm_content=3Dwebmail&amp;utm_term=
=3Dlink" style=3D"color:rgb(68,83,234)" target=3D"_blank">www.avast.com</a>
		</td>
	</tr>
</tbody></table><a width=3D"1" height=3D"1"></a></div>
</div></blockquote></div><br></div></div></div></blockquote></div>

--0000000000005c0eab057caec26c--