1 % tunet und eduroam down...
10 ip.addr == 192.168.67.83
14 No. -> generated while monitoring
16 Source IP (192.168.67.83), Destination IP (192.168.67.37), Protocol (UDP), Length (82), TTL (64), Dest port (118), Flags (empty), Frag offset (0)
22 repeating transfers, transfers seem separable over time via the udp.srcport attribute
24 filtered traffic via wireshark again by source port 51899
28 reimported to rapidminer
31 dscp + timing changes.
33 the DSCP value grows until 10962
35 then it's fixed on DSCP 10962
44 some bits are broken, as the timing and my decodes is more a hack.
46 a hack is a hack is a hack ... :)
51 rescan... new ip: 192.168.67.26
55 ip.src == 192.168.67.0/24 and ip.dst == 192.168.67.0/24
57 10min\_localnet.{pcap,csv}
59 look at it via rapidminer (filter away gateway (.1) and self (.26) as sources)
60 image:stream\_localnet.pdf
62 image:stream\_localnet\_ports.pdf
63 dest ports are always first 80/udp, then 443/udp, then 465/tcp, then 464/udp
64 always from first .83, then .82, then .81, then .84
66 filtered for one complete transaction
67 udp.port == 58493 or udp.port == 45875 or tcp.port == 40875 or udp.port == 36842
68 10min\_transaction.{pcap,csv}
72 %filtered away nfs and ssh
73 %!(tcp.port == 666 || tcp.port == 2049)
76 %look at it via rapidminer
79 %((ip.addr eq 192.168.67.81 or ip.addr eq 192.168.67.82 or ip.addr eq 192.168.67.83) and ip.addr eq 192.168.67.37)
82 %look at it again via rapidminer
83 %image:stream\_better.pdf
85 %dest ports are always first 80/udp, then 443/udp, then 465/tcp
87 %filtered for one complete transaction
88 %tcp.port == 56533 or udp.port == 50293 or udp.port == 56040
91 %look at it again via rapidminer
92 %image:stream\_cool.pdf
94 %%%%%%%%%%%%%%%%%%%%%%%
98 No. -> generated while monitoring
100 TTL (64), Frag offset (0)
103 does not look like timing, packets arrive in almost equal distances (10ms sequence)
109 0x0018: ACK,PSH (600x)
112 Expected distribution of values
115 not a high variance detected:
117 \item UDP Stream from 192.168.67.83:56040 to 192.168.67.37:80 %TODO fix
118 \item UDP Stream from 192.168.67.82:50293 to 192.168.67.37:443 %TODO fix
119 \item TCP Traffic between 192.168.67.81:56533 to 192.168.67.37:465 %TODO fix
120 \imte UDP Stream from 192.168.67.84:36842 to 192.168.67.26:464
123 Length also does not vary very much:
125 \item Length 60 for Source Port 56040/udp
126 \item Length 60 for Source Port 52093/udp
127 \item Length 70 for ACK,PSH (600x), 74 for SYN (1x), 66 for ACK (1x) and 66 for FIN (1x) for Source Port 56533/tcp
128 \item Length 66 for ACK, 74 for SYN,ACK for Source Port 465/tcp
129 \item %TODO fix for sport 464
135 Unknown, because we do have two shorter transmissions before a longer transmission from different source ips
138 Not yet. We do not know if the three transmissions are connected to each other
140 Most likely it is in the DSCP field of the third transmission. (This also has responses from the local system)