Traffic Trace Info


DumpFile: 201005181400.dump
FileSize: 2708.07MB
Id: 201005181400
StartTime: Tue May 18 14:00:01 2010
EndTime: Tue May 18 14:15:00 2010
TotalTime: 899.27 seconds
TotalCapSize: -1975.95MB CapLen: 96 bytes
# of packets: 38536081 (24774.22MB)
AvgRate: 231.10Mbps stddev:15.96M

IP flow (unique src/dst pair) Information

# of flows: 1064903 (avg. 36.19 pkts/flow)
Top 10 big flow size (bytes/total in %):
1.9% 1.5% 1.5% 1.1% 1.1% 1.0% 1.0% 0.9% 0.9% 0.8%

IP address Information

# of IPv4 addresses: 585251
Top 10 bandwidth usage (bytes/total in %):
13.4% 9.0% 8.4% 6.6% 5.0% 3.5% 3.3% 2.7% 2.0% 2.0%
# of IPv6 addresses: 1120
Top 10 bandwidth usage (bytes/total in %):
31.1% 9.2% 6.6% 5.1% 4.8% 4.0% 4.0% 3.0% 3.0% 2.9%

Packet Size Distribution (including MAC headers)

[packet size distribution]
detailed numbers
 [   32-   63]:    6743312
 [   64-  127]:   10246133
 [  128-  255]:    2645205
 [  256-  511]:    1925935
 [  512- 1023]:    1054800
 [ 1024- 2047]:   15920696


Protocol Breakdown

[protocol breakdown chart]

     protocol		packets			bytes		bytes/pkt
------------------------------------------------------------------------
 total         38536081 (100.00%)      25977657723 (100.00%)    674.11
 ip            38484580 ( 99.87%)      25966434217 ( 99.96%)    674.72
  tcp          24063368 ( 62.44%)      18838053370 ( 72.52%)    782.85
   http(s)     10505509 ( 27.26%)      14237851738 ( 54.81%)   1355.27
   http(c)      7564324 ( 19.63%)       1093540863 (  4.21%)    144.57
   squid         349405 (  0.91%)         88318708 (  0.34%)    252.77
   smtp          496641 (  1.29%)        266006307 (  1.02%)    535.61
   nntp             114 (  0.00%)             7894 (  0.00%)     69.25
   ftp            57077 (  0.15%)          9492819 (  0.04%)    166.32
   pop3           13201 (  0.03%)          5761537 (  0.02%)    436.45
   imap            4923 (  0.01%)          2502287 (  0.01%)    508.28
   telnet          4412 (  0.01%)           354420 (  0.00%)     80.33
   ssh            77435 (  0.20%)         28786566 (  0.11%)    371.75
   dns            23529 (  0.06%)          1715872 (  0.01%)     72.93
   bgp              164 (  0.00%)            64698 (  0.00%)    394.50
   napster           19 (  0.00%)             2056 (  0.00%)    108.21
   realaud            5 (  0.00%)              355 (  0.00%)     71.00
   rtsp          336769 (  0.87%)        151747542 (  0.58%)    450.60
   icecast        10494 (  0.03%)           877427 (  0.00%)     83.61
   hotline            9 (  0.00%)              758 (  0.00%)     84.22
   other        4619335 ( 11.99%)       2951021343 ( 11.36%)    638.84
  udp          10183027 ( 26.42%)       4838167306 ( 18.62%)    475.12
   dns           822645 (  2.13%)        143111763 (  0.55%)    173.97
   realaud         2076 (  0.01%)          2230844 (  0.01%)   1074.59
   halflif           34 (  0.00%)             3009 (  0.00%)     88.50
   starcra           91 (  0.00%)            11080 (  0.00%)    121.76
   everque          665 (  0.00%)           164286 (  0.00%)    247.05
   unreal            46 (  0.00%)             6660 (  0.00%)    144.78
   quake             25 (  0.00%)             4435 (  0.00%)    177.40
   cuseeme            4 (  0.00%)              353 (  0.00%)     88.25
   other        9356900 ( 24.28%)       4692494147 ( 18.06%)    501.50
  icmp           445736 (  1.16%)         99797030 (  0.38%)    223.89
  ipip              357 (  0.00%)            43774 (  0.00%)    122.62
  ipsec             983 (  0.00%)           172778 (  0.00%)    175.77
  ip6           3753531 (  9.74%)       2184166393 (  8.41%)    581.90
  other           37578 (  0.10%)          6033566 (  0.02%)    160.56
  frag             3500 (  0.01%)          2873801 (  0.01%)    821.09
 ip6              51501 (  0.13%)         11223506 (  0.04%)    217.93
  tcp6             9288 (  0.02%)          1959729 (  0.01%)    211.00
   http(s)          251 (  0.00%)           236186 (  0.00%)    940.98
   http(c)         1318 (  0.00%)           127835 (  0.00%)     96.99
   squid              9 (  0.00%)             2992 (  0.00%)    332.44
   smtp             192 (  0.00%)            84325 (  0.00%)    439.19
   imap             356 (  0.00%)            41537 (  0.00%)    116.68
   ssh             2502 (  0.01%)           782772 (  0.00%)    312.86
   dns              513 (  0.00%)            76961 (  0.00%)    150.02
   bgp              123 (  0.00%)            22949 (  0.00%)    186.58
   other           4024 (  0.01%)           584172 (  0.00%)    145.17
  udp6            36050 (  0.09%)          8361573 (  0.03%)    231.94
   dns            35159 (  0.09%)          8210286 (  0.03%)    233.52
   other            891 (  0.00%)           151287 (  0.00%)    169.79
  icmp6            6039 (  0.02%)           817049 (  0.00%)    135.30
  pim6               31 (  0.00%)             4216 (  0.00%)    136.00
  other6             93 (  0.00%)            80939 (  0.00%)    870.31


tcpdump file: 201005181400.dump.gz (1000.91 MB)