Re: TCP flags packet counting
Masoud Sadri <[email protected]> Mon, 10 Dec 2018 21:27:09 +0330
| Newsgroups | gmane.network.argus |
|---|---|
| Message-ID | <CAAyATt-kLEonY_n6O+0LJKRf9SmTZeMLryJdtHzYZMSJUeBUPA@mail.gmail.com> |
--0000000000005c0eab057caec26c Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Thanks for your reply. My thesis is about finding the anomaly in network flows. I used Johan Mazel thesis[1] as the base of my work. As you can see in section 3.1.2, "Multi-resolution Flow Aggregation"; he aggregated network flows and extracted nine features from them. Two of them(nRST/nPkts and nSYN/nPkts) depend on TCP flags counter field. Masoud [1] https://tel.archives-ouvertes.fr/tel-00667654/document On Sun, Dec 9, 2018 at 5:36 PM <[email protected]> wrote: > Hey Masoud, > We don=E2=80=99t track the number of packet types in a TCP connection, no= t > something that has come up in a few decades. It would be easy to do, and > would involve extending the TCP DSR to add counters for each flag type, a= nd > of course all their combinations. But as I mentioned, no one has been > looking for those metrics. > > Can you tell us why this is important to your thesis ??? Are you doing > something for security or operations ??? > > Carter > > On Dec 8, 2018, at 3:01 PM, Masoud Sadri <[email protected]> wrote: > > Hi, > In addition of total packets in each record I need to know the number of > syn,ack,fin,rst,urg,psh,cwr,ece packets separably. > Could you help me, please? > > > <https://www.avast.com/sig-email?utm_medium=3Demail&utm_source=3Dlink&utm= _campaign=3Dsig-email&utm_content=3Dwebmail&utm_term=3Dicon> Virus-free. > www.avast.com > <https://www.avast.com/sig-email?utm_medium=3Demail&utm_source=3Dlink&utm= _campaign=3Dsig-email&utm_content=3Dwebmail&utm_term=3Dlink> > > > --0000000000005c0eab057caec26c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div>Thanks for your rep= ly.</div><div>My thesis is about finding the anomaly in network flows. I us= ed Johan Mazel thesis[1] as the base of my work. As you can see in section = 3.1.2, "Multi-resolution Flow Aggregation"; he aggregated network= flows and extracted nine features from them. Two of them(nRST/nPkts and nSYN/nPkts) depend on TCP flags counter field.</div><div><br></div><di= v>Masoud</div><div><br></div><div>[1]=C2=A0<a href=3D"https://tel.archives-= ouvertes.fr/tel-00667654/document" target=3D"_blank">https://tel.archives-o= uvertes.fr/tel-00667654/document</a>=C2=A0=C2=A0<br></div></div></div></div= ><br><div class=3D"gmail_quote"><div dir=3D"ltr">On Sun, Dec 9, 2018 at 5:3= 6 PM <<a href=3D"mailto:[email protected]" target=3D"_blank">carter@qos= ient.com</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D= "margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-le= ft:1ex"><div>Hey Masoud,<div>We don=E2=80=99t track the number of packet ty= pes in a TCP connection, not something that has come up in a few decades.= =C2=A0 It would be easy to do, and would involve extending the TCP DSR to a= dd counters for each flag type, and of course all their combinations.=C2=A0= But as I mentioned, no one has been looking for those metrics. =C2=A0</div= ><div><br></div><div>Can you tell us why this is important to your thesis ?= ??=C2=A0 Are you doing something for security or operations ???</div><div><= br><div>Carter =C2=A0<div><br><blockquote type=3D"cite"><div>On Dec 8, 2018= , at 3:01 PM, Masoud Sadri <<a href=3D"mailto:[email protected]" tar= get=3D"_blank">[email protected]</a>> wrote:</div><br class=3D"gmail= -m_8033978383335197755gmail-m_3971965068078662434Apple-interchange-newline"= ><div><div dir=3D"ltr"><div>Hi,</div><div class=3D"gmail-m_8033978383335197= 755gmail-m_3971965068078662434fonttools-rtl"><div>In addition of total pack= ets in each record I need to know the number of syn,ack,fin,rst,urg,psh,cwr= ,ece packets separably.=C2=A0</div><div>Could you help me, please?</div></d= iv></div><div id=3D"gmail-m_8033978383335197755gmail-m_3971965068078662434D= AB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br> <table style=3D"border-top:1px solid rgb(211,212,222)"> <tbody><tr> <td style=3D"width:55px;padding-top:13px"><a href=3D"https://www.av= ast.com/sig-email?utm_medium=3Demail&utm_source=3Dlink&utm_campaign= =3Dsig-email&utm_content=3Dwebmail&utm_term=3Dicon" target=3D"_blan= k"><img alt=3D"" width=3D"46" height=3D"29" style=3D"width: 46px; height: 2= 9px;"></a></td> <td style=3D"width:470px;padding-top:12px;color:rgb(65,66,78);font-size:1= 3px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free. <a= href=3D"https://www.avast.com/sig-email?utm_medium=3Demail&utm_source= =3Dlink&utm_campaign=3Dsig-email&utm_content=3Dwebmail&utm_term= =3Dlink" style=3D"color:rgb(68,83,234)" target=3D"_blank">www.avast.com</a> </td> </tr> </tbody></table><a width=3D"1" height=3D"1"></a></div> </div></blockquote></div><br></div></div></div></blockquote></div> --0000000000005c0eab057caec26c--