Analyzing Packet Interarrival Times Distribution to Detect Network Bottlenecks

  • Pál Varga
Part of the IFIP International Federation for Information Processing book series (IFIPAICT, volume 196)


This paper analyzes the properties of packet interarrival time (PIT) distribution functions of network segments including bottlenecks. In order to show the correlation between bottleneck behavior and packet interarrival time distribution, the alteration of probability distribution function (PDF) is observed through simulations including tighter and tighter bottleneck connections. The process of network bottleneck detection by passive monitoring requires effective metrics for distinguishing seriously congested links from normal or underutilized connections. The paper evaluates the third and fourth central moments (skewness and kurtosis, respectively) of PIT distribution as possible metrics for bottleneck detection. Simulation results as well as real measurement data analysis showed that PIT kurtosis can be a powerful measure of bottleneck behavior.


passive monitoring bottleneck detection kurtosis 


  1. Carter, Robert L. and Crovella, M. E. (1996). Measuring bottleneck link speed in packet-switched networks. Performance Evaluation, 27–28:297–318.Google Scholar
  2. Darlington, R.B. (1970). Is kurtosis really peakedness? American Statistician, 24(19–22).Google Scholar
  3. Kang, S., Liu, X., Dai, M., and Loguinov, D. (2004). Packet-pair bandwidth estimation: Stochastic analysis of a single congested node. In Proceedings of IEEE ICNP 2004.Google Scholar
  4. Katabi, D. and Blake, C. (2002). Inferring congestion sharing and path characteristics from packet interarrival times. Technical report, MIT-LCS-TR-828, MIT.Google Scholar
  5. Kenney, J. F. and Keeping, E. S. (1951). Mathematics of Statistics, volume 2. Princeton, NJ: Van Nostrand, 2nd edition.Google Scholar
  6. Keshav, S. (1991). A control-theoretic approach to flow control. In Proceedings of SIGCOMM.Google Scholar
  7. Moldován, I., Dang, T. Dinh, Bíró, J., Satoh, D., and Ishibashi, K. (2004). Bottleneck links detection method based on passive monitoring. In Iasted CIIT 2004.Google Scholar
  8. Molnár, S. and Miklós, Gy. (1998). Peakedness characterization in teletraffic. In IFIP TC6, WG6.3 conference PICS’98.Google Scholar
  9. Pearson, K. (1905). Das fehlergesetz und seine verallgemeinerungen durch fechner und pearson. Biometrika, 169–212.Google Scholar
  10. Riedl, A., Perske, M., Bauschert, T., and Probst, A. (2000). Dimensioning of ip access networks with elastic traffic. In First Polish-German Teletraffic Symposium (PGTS 2000).Google Scholar
  11. Varga, P. and Kún, G. (2005). Utilizing higher order statistics of packet interarrival times for bottleneck detection. In Proceedings of IFIP/IEEE E2EMon.Google Scholar
  12. Varga, P., Kún, G., Fodor, P., Bíró, J., Satoh, D., and Ishibashi, K. (2003). An advanced technique on bottleneck detection. In IFIP WG6.3 workshop, EUNICE 2003.Google Scholar
  13. Varga, P., Moldován, I., Dang, T. Dinh, Simon, Cs., Kún, G., and Tatai, P. (2004). Developing a passive measurement-based methodology for detecting network bottlenecks in ip networks. Technical report, Study for Hungarian Telecom, in Hungarian.Google Scholar

Copyright information

© International Federation for Information Processing 2006

Authors and Affiliations

  • Pál Varga
    • 1
  1. 1.Department of Telecommunications and Media InformaticsBudapest University of Technology and Economics (BME-TMIT)BudapestHungary

Personalised recommendations