We present our architecture in Figure 1. Three logical components
form our system: CMON, Flow Daemon and TAPS. On our
network, traffic tapping of optical links is performed by CMON [13]
systems. While CMON has other statistical analytical capabilities,
we use it to simply monitor packet traffic and output NetFlow (V5)
style flow information. It exports a five tuple flow - source IP, destination
IP, source port, destination port, protocol. Endace’s commercial
Ninja probe, or any router or appliance that output unsampled
NetFlow (V5) with accurate timestamps can achieve the same
effect. We choose CMON due to its availability, in house knowledge
and cost. CMON is capable of monitoring backbone links up
to link speeds of OC-192.