Author: Gallerani, L.
Paper Title Page
WEPGF045 Large Graph Visualization of Millions of Connections in the CERN Control System Network Traffic: Analysis and Design of Routing and Firewall Rules with a New Approach 799
 
  • L. Gallerani
    CERN, Geneva, Switzerland
 
  The CERN Tech­ni­cal Net­work (TN) TN was in­tended to be a net­work for ac­cel­er­a­tor and in­fra­struc­ture op­er­a­tions. How­ever, today, more than 60 Mil­lion IP pack­ets are routed every hour be­tween the Gen­eral Pur­pose Net­work (GPN) and the TN in­volv­ing more than 6000 dif­fer­ent hosts. In order to im­prove the se­cu­rity of the ac­cel­er­a­tor con­trol sys­tem, it is fun­da­men­tal to un­der­stand the net­work traf­fic be­tween the two net­works in order to de­fine ap­pro­pri­ate rout­ing and fire­wall rules with­out im­pact­ing Op­er­a­tions. The com­plex­ity and huge size of the in­fra­struc­ture and the num­ber of pro­to­cols and ser­vices in­volved have dis­cour­aged for years any at­tempt to un­der­stand and con­trol the net­work traf­fic be­tween the GPN and the TN. In this talk, we will show a new way to solve the prob­lem graph­i­cally. Com­bin­ing the net­work traf­fic analy­sis with the use of large graph vi­su­al­iza­tion al­go­rithms we pro­duce com­pre­hen­si­ble and us­able 2D large colour topol­ogy graphs map­ping the com­plex net­work re­la­tions of the con­trol sys­tem ma­chines and ser­vices in a de­tail and clar­ity never seen be­fore. The talk in­te­grates very in­ter­est­ing pic­tures and video of the graph­i­cal analy­sis at­tempt.  
poster icon Poster WEPGF045 [6.809 MB]  
Export • reference for this paper using ※ BibTeX, ※ LaTeX, ※ Text/Word, ※ RIS, ※ EndNote (xml)