Date Added: Sep 2009
This paper discusses the need for accurate analysis of TCP connections based on aggregated flow information. Due to increasing bandwidths in the Internet, flow metering is thought to be the a promising solution for network monitoring, because packet-oriented state-based analysis reaches its limits and fast hardware support for flow metering is already integrated in modern routers. Motivated by earlier work on flow-based connection analysis, the author investigates the quality of several stateless classifiers that can be used to determine the TCP connection state as either successful or failed. This information is strongly needed especially in the domain of attack detection and is usually produced by fine-grained analysis in the packet level.