1 % tunet und eduroam down...
10 ip.addr == 192.168.67.83
14 No. -> generated while monitoring
16 Source IP (192.168.67.83), Destination IP (192.168.67.37), Protocol (UDP), Length (82), TTL (64), Dest port (118), Flags (empty), Frag offset (0)
22 repeating transfers, transfers seem separable over time via the udp.srcport attribute
24 filtered traffic via wireshark again by source port 51899
28 reimported to rapidminer
31 dscp + timing changes.
33 the DSCP value grows until 10962
35 then it's fixed on DSCP 10962
44 some bits are broken, as the timing and my decodes is more a hack.
46 a hack is a hack is a hack ... :)
51 rescan... new ip: 192.168.67.26
55 ip.src == 192.168.67.0/24 and ip.dst == 192.168.67.0/24
57 10min\_localnet.{pcap,csv}
59 look at it via rapidminer (filter away gateway (.1) and self (.26) as sources)
60 image:stream\_localnet.pdf
62 image:stream\_localnet\_ports.pdf
63 dest ports are always first 80/udp, then 443/udp, then 465/tcp, then 464/udp
64 always from first .83, then .82, then .81, then .84
69 %filtered away nfs and ssh
70 %!(tcp.port == 666 || tcp.port == 2049)
73 %look at it via rapidminer
76 %((ip.addr eq 192.168.67.81 or ip.addr eq 192.168.67.82 or ip.addr eq 192.168.67.83) and ip.addr eq 192.168.67.37)
79 %look at it again via rapidminer
80 %image:stream\_better.pdf
82 %dest ports are always first 80/udp, then 443/udp, then 465/tcp
84 %filtered for one complete transaction
85 %tcp.port == 56533 or udp.port == 50293 or udp.port == 56040
88 %look at it again via rapidminer
89 %image:stream\_cool.pdf
91 %%%%%%%%%%%%%%%%%%%%%%%
95 No. -> generated while monitoring
97 TTL (64), Frag offset (0)
100 does not look like timing, packets arrive in almost equal distances (10ms sequence)
106 0x0018: ACK,PSH (600x)
109 Expected distribution of values
112 not a high variance detected:
114 \item UDP Stream from 192.168.67.83:56040 to 192.168.67.37:80 %TODO fix
115 \item UDP Stream from 192.168.67.82:50293 to 192.168.67.37:443 %TODO fix
116 \item TCP Traffic between 192.168.67.81:56533 to 192.168.67.37:465 %TODO fix
117 \imte UDP Stream from 192.168.67.84:36842 to 192.168.67.26:464
120 Length also does not vary very much:
122 \item Length 60 for Source Port 56040/udp
123 \item Length 60 for Source Port 52093/udp
124 \item Length 70 for ACK,PSH (600x), 74 for SYN (1x), 66 for ACK (1x) and 66 for FIN (1x) for Source Port 56533/tcp
125 \item Length 66 for ACK, 74 for SYN,ACK for Source Port 465/tcp
126 \item %TODO fix for sport 464
132 Unknown, because we do have two shorter transmissions before a longer transmission from different source ips
135 Not yet. We do not know if the three transmissions are connected to each other
137 Most likely it is in the DSCP field of the third transmission. (This also has responses from the local system)