Zoom Network Traffic Analysis Tools
===================================

The following software tools were developed and used
for Zoom network traffic analysis in the PAM 2022 paper
"Zoom Session-Quality: A Network Level View" by Choi et al.

---------------------------------------------------------------

These three C programs all work with connection-level Zoom data,
in a slightly reduced format from standard Zeek connection logs.
The files must be properly formatted, and in sorted timestamp order.

example1.txt: the small example from Appendix 1 of the paper.
  This file was constructed by extracting the required columns
  from the Zeek connection log example1.dat using this command:
  % awk '{print $1,$3,$4,$5,$6,$7,$9,$12,$17,$18,$19,$20}' example1.dat > example1.txt

example2.txt: anonymized version of "Zoom lecture class" from the paper.

example3.txt: anonymized version of "large Zoom meeting" from the paper.

zoomparse.c: parses a text-based Zoom connection log file
and prints things in a standardized form with the client IP
on the left, and the Zoom server IP (if any) on the right,
and some blank lines to show any gaps in the relative timing.
This is mostly for sanity checking on the parsing, which is
exactly the same in the subsequent tools as well.

zoomplot.c: does things similar to the above, except with
relative timestamps (in seconds) throughout, and no extraneous
blank lines. It also adds some additional columns (connID, ipID)
so that the data can be plotted by the gnuplot scripts below.

zoomcount.c: tries to group related TCP and UDP connections
together into a logical Zoom session (presumably 1 human)
and report some simple statistics about each session.
It also guesses which UDP channels are audio (A), video (V),
and screen-sharing data (D), using simple heuristics and thresholds.
It is not perfect at this, but does a reasonably good job.

zoom.gnuplot: a plotting script that makes the graphs
for Zoom session profile plots. These include the connection
profile graph, the port profile graph, and the IP profile
graph, which are all time-series plots. It can also generate
scatterplots of average packet sizes and average packet rates
(if you enable those commands in the gnuplot file).

---------------------------------------------------------------

zoom-conn-parser.py: this is a Python program for identifying
Zoom meetings within connection-level data that has labels on the
Zoom server types. This program was written by Mehdi Karamollahi.

zoom-conn-example.txt: an example of the file format with
labeled Zoom server types, output from our Vertica SQL scripts.

---------------------------------------------------------------

Please see the "howto.txt" file for instructions and tips.
Let the authors know if you have any questions or problems.

Carey Williamson (March 19, 2022)
