Summary items

The Summary view provides statistics changed along with Analysis Profile and the node in the Node Explorer window.

With Full Analysis and choosing the root node on Node Explorer window, the statistics items for Summary view include:

Item Type Item Description
Diagnosis Information Events, Notice Events, Warning Events, Error Events List the number of each event type (See Diagnosis for more information)
Traffic Total, Broadcast, Multicast, Average Packet Size

List byte, packet number, utilization, bps, packets per second of each traffic type

  • Over 50% of total traffic utilization: network may be overloaded
  • Over 20% of broadcast or multicast traffic utilization: broadcast/multicast storm and ARP attack
Packet Size Distribution <=64, 65-127, 128-255, 256-511, 512-1023,1024-1517, >=1518

List byte, packet number, utilization, bps, packets per second of each packet size type

Large portion of traffic at <=64 or >=1518: fragment attack or flood attack

Address MAC Address, IP Address, Local IP Address, Remote IP address

List the number of each address type

Too large number: MAC flooding attack, TCP flooding attack, etc.

Protocol Total Protocols, Data Link Layer, Network Layer, Transport Layer, Session Layer, Presentation Layer, Application Layer List the number of total protocols and protocols of six layers
Conversation Physical Conversations, IP Conversations, TCP Conversations, UDP Conversations List the number of four types of conversation
TCP TCP SYN Sent, TCP SYNACK Sent, TCP FIN Sent, TCP Reset Sent (plus TCP SYN Received, TCP SYNACK Sent, TCP FIN Received and TCP Reset Received when a specific node of IP Explorer is selected)

List the number of each flag of TCP conversation

Large number of TCP SYN packets: port scanning (TCP SYN flooding attack)

Alarm Security Alarms, Performance Alarms, Fault Alarms List the number of each alarm type
DNS Analysis DNS Queries, DNS Responses

List the number of DNS query and response

This type of statistics will not display in the analysis profiles of Email Analysis, FTP Analysis and HTTP Analysis.

Email Analysis SMTP Connections, POP3 Connections

List the number of SMTP and POP3 connections

This type of statistics will not display in the analysis profiles of DNS Analysis, FTP Analysis and HTTP Analysis.

FTP Analysis FTP Upload, FTP Download

List the number of FTP upload and download

This type of statistics will not display in the analysis profiles of DNS Analysis, Email Analysis and HTTP Analysis.

HTTP Analysis HTTP Request Sent, HTTP Request Received, HTTP Connections

List the number of HTTP application

This type of statistics will not display in the analysis profiles of DNS Analysis, Email Analysis and FTP Analysis.

Back