AMON: An Open Source Architecture for Online Monitoring, Statistical Analysis and Forensics of Multi-gigabit Streams
Michael Kallitsis, Stilian Stoev, Shrijita Bhattacharya, George, Michailidis

TL;DR
AMON is an open-source system designed for real-time monitoring and analysis of high-speed network traffic, enabling quick detection and diagnosis of network attacks like DDoS.
Contribution
It introduces a scalable, high-performance architecture for online network traffic analysis that integrates real-time detection, visualization, and forensic capabilities on commodity hardware.
Findings
Successfully processes 10Gbps+ live Internet traffic
Effective detection of high-impact network events like DDoS
Validated against state-of-the-art monitoring tools
Abstract
The Internet, as a global system of interconnected networks, carries an extensive array of information resources and services. Key requirements include good quality-of-service and protection of the infrastructure from nefarious activity (e.g. distributed denial of service--DDoS--attacks). Network monitoring is essential to network engineering, capacity planning and prevention / mitigation of threats. We develop an open source architecture, AMON (All-packet MONitor), for online monitoring and analysis of multi-gigabit network streams. It leverages the high-performance packet monitor PF RING and is readily deployable on commodity hardware. AMON examines all packets, partitions traffic into sub-streams by using rapid hashing and computes certain real-time data products. The resulting data structures provide views of the intensity and connectivity structure of network traffic at the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
