Traffic Trace Info


DumpFile: 201307261400.dump
FileSize: 3887.75MB
Id: 201307261400
StartTime: Fri Jul 26 14:00:01 2013
EndTime: Fri Jul 26 14:15:00 2013
TotalTime: 899.17 seconds
TotalCapSize: -1095.28MB CapLen: 96 bytes
# of packets: 58130512 (31602.38MB)
AvgRate: 294.74Mbps stddev:58.17M

IP flow (unique src/dst pair) Information

# of flows: 20745003 (avg. 2.80 pkts/flow)
Top 10 big flow size (bytes/total in %):
8.7% 1.8% 1.8% 1.3% 1.1% 1.1% 1.1% 1.1% 1.0% 1.0%

IP address Information

# of IPv4 addresses: 16796514
Top 10 bandwidth usage (bytes/total in %):
9.5% 9.1% 9.1% 9.0% 4.6% 3.9% 3.3% 2.9% 2.6% 2.3%
# of IPv6 addresses: 12357
Top 10 bandwidth usage (bytes/total in %):
17.7% 8.4% 8.2% 8.1% 7.8% 5.6% 4.9% 4.8% 4.2% 3.9%

Packet Size Distribution (including MAC headers)

[packet size distribution]
detailed numbers
 [   32-   63]:   26270700
 [   64-  127]:    8721204
 [  128-  255]:    1157750
 [  256-  511]:    1045009
 [  512- 1023]:     889229
 [ 1024- 2047]:   20046620


Protocol Breakdown

[protocol breakdown chart]

     protocol		packets			bytes		bytes/pkt
------------------------------------------------------------------------
 total         58130512 (100.00%)      33137492136 (100.00%)    570.05
 ip            55788085 ( 95.97%)      31494861665 ( 95.04%)    564.54
  tcp          30221573 ( 51.99%)      28576247315 ( 86.24%)    945.56
   http(s)     16382077 ( 28.18%)      20372413534 ( 61.48%)   1243.58
   http(c)      9305507 ( 16.01%)       3597626969 ( 10.86%)    386.61
   squid         151482 (  0.26%)         23230499 (  0.07%)    153.35
   smtp           84868 (  0.15%)         31513355 (  0.10%)    371.32
   nntp               2 (  0.00%)              120 (  0.00%)     60.00
   ftp            55373 (  0.10%)         27609852 (  0.08%)    498.62
   pop3            3722 (  0.01%)          1484471 (  0.00%)    398.84
   imap            6052 (  0.01%)           747044 (  0.00%)    123.44
   telnet          2896 (  0.00%)          1675975 (  0.01%)    578.72
   ssh            95510 (  0.16%)         16871002 (  0.05%)    176.64
   dns             6096 (  0.01%)          3565071 (  0.01%)    584.82
   bgp              543 (  0.00%)           120677 (  0.00%)    222.24
   napster           12 (  0.00%)             1861 (  0.00%)    155.08
   realaud            2 (  0.00%)              120 (  0.00%)     60.00
   rtsp               4 (  0.00%)              240 (  0.00%)     60.00
   icecast        43713 (  0.08%)          8559527 (  0.03%)    195.81
   hotline           10 (  0.00%)              676 (  0.00%)     67.60
   other        4083704 (  7.03%)       4490826322 ( 13.55%)   1099.69
  udp           2928761 (  5.04%)       1357256314 (  4.10%)    463.42
   dns          1296781 (  2.23%)        601800335 (  1.82%)    464.07
   rip                2 (  0.00%)              177 (  0.00%)     88.50
   realaud            9 (  0.00%)             1033 (  0.00%)    114.78
   halflif         1212 (  0.00%)           137810 (  0.00%)    113.70
   starcra           66 (  0.00%)             6340 (  0.00%)     96.06
   everque           45 (  0.00%)             7621 (  0.00%)    169.36
   unreal             7 (  0.00%)              913 (  0.00%)    130.43
   quake             20 (  0.00%)             1812 (  0.00%)     90.60
   cuseeme            8 (  0.00%)              828 (  0.00%)    103.50
   other        1629751 (  2.80%)        755109104 (  2.28%)    463.33
  icmp         22002938 ( 37.85%)       1371076359 (  4.14%)     62.31
  ipip              185 (  0.00%)            19270 (  0.00%)    104.16
  ipsec           17749 (  0.03%)          7097738 (  0.02%)    399.90
  ip6            393130 (  0.68%)         99914903 (  0.30%)    254.15
  other          223749 (  0.38%)         83249766 (  0.25%)    372.07
  frag           717391 (  1.23%)        949875213 (  2.87%)   1324.07
 ip6            2342427 (  4.03%)       1642630471 (  4.96%)    701.25
  tcp6          2183180 (  3.76%)       1607253954 (  4.85%)    736.20
   http(s)      1107207 (  1.90%)       1232307214 (  3.72%)   1112.99
   http(c)       840856 (  1.45%)         76976415 (  0.23%)     91.55
   smtp              69 (  0.00%)            17167 (  0.00%)    248.80
   ftp              949 (  0.00%)           110104 (  0.00%)    116.02
   pop3             264 (  0.00%)           229302 (  0.00%)    868.57
   ssh               78 (  0.00%)            12894 (  0.00%)    165.31
   dns              303 (  0.00%)            53083 (  0.00%)    175.19
   bgp               95 (  0.00%)            26691 (  0.00%)    280.96
   other         233359 (  0.40%)        297521084 (  0.90%)   1274.95
  udp6           117435 (  0.20%)         29416715 (  0.09%)    250.49
   dns           115440 (  0.20%)         29199034 (  0.09%)    252.94
   starcra            1 (  0.00%)              111 (  0.00%)    111.00
   everque            4 (  0.00%)              396 (  0.00%)     99.00
   quake              2 (  0.00%)              275 (  0.00%)    137.50
   other           1988 (  0.00%)           216899 (  0.00%)    109.10
  icmp6           40850 (  0.07%)          5032447 (  0.02%)    123.19
  pim6               30 (  0.00%)             4080 (  0.00%)    136.00
  other6            932 (  0.00%)           923275 (  0.00%)    990.64


tcpdump file: 201307261400.dump.gz (1226.78 MB)