# Project 2: Web Traffic Analysis
**This is the second of three mandatory projects to be handed in as part of the assessment for the course 02807 Computational Tools for Data Science at Technical University of Denmark, autumn 2019.**

#### Practical info
- **The project is to be done in groups of at most 3 students**
- **Each group has to hand in _one_ Jupyter notebook (this notebook) with their solution**
- **The hand-in of the notebook is due 2019-11-10, 23:59 on DTU Inside**

#### Your solution
- **Your solution should be in Python**
- **For each question you may use as many cells for your solution as you like**
- **You should document your solution and explain the choices you've made (for example by using multiple cells and use Markdown to assist the reader of the notebook)**
- **You should not remove the problem statements**
- **Your notebook should be runnable, i.e., clicking [>>] in Jupyter should generate the result that you want to be assessed**
- **You are not expected to use machine learning to solve any of the exercises**
- **You will be assessed according to correctness and readability of your code, choice of solution, choice of tools and libraries, and documentation of your solution**

## Introduction
In this project your task is to analyze a stream of log entries. A log entry consists of an [IP address](https://en.wikipedia.org/wiki/IP_address) and a [domain name](https://en.wikipedia.org/wiki/Domain_name). For example, a log line may look as follows:

`192.168.0.1 somedomain.dk`

One log line is the result of the event that the domain name was visited by someone having the corresponding IP address. Your task is to analyze the traffic on a number of domains. Counting the number of unique IPs seen on a domain doesn't correspond to the exact number of unique visitors, but it is a good estimate.

Specifically, you should answer the following questions from the stream of log entries.

- How many unique IPs are there in the stream?
- How many unique IPs are there for each domain?
- How many times was IP X seen on domain Y? (for some X and Y provided at run time)

**The answers to these questions can be approximate!**

You should also try to answer one or more of the following, more advanced, questions. The answers to these should also be approximate.

- How many unique IPs are there for the domains $d_1, d_2, \ldots$?
- How many times was IP X seen on domains $d_1, d_2, \ldots$?
- What are the X most frequent IPs in the stream?

You should use algorithms and data structures that you've learned about in the lectures, and you should provide your own implementations of these.

Furthermore, you are expected to:

- Document the accuracy of your answers when using algorithms that give approximate answers
- Argue why you are using certain parameters for your data structures

This notebook is in three parts. In the first part you are given an example of how to read from the stream (which for the purpose of this project is a remote file). In the second part you should implement the algorithms and data structures that you intend to use, and in the last part you should use these for analyzing the stream.

## Reading the stream
The following code reads a remote file line by line. It is wrapped in a generator to make it easier to extend. You may modify this if you want to, but your solution should remain parametrized, so that your notebook can be run without having to consume the entire file.

In [6]:
from urllib.request import urlopen

def stream(n):
    i = 0
    with urlopen('https://files.dtu.dk/fss/public/link/public/stream/read/traffic_2?linkToken=_DcyO-U3MjjuNzI-&itemName=traffic_2') as f:
        for line in f:
            element = line.rstrip().decode("utf-8")
            yield element
            i += 1
            if i == n:
                break

In [7]:
STREAM_SIZE = 10
web_traffic_stream = stream(STREAM_SIZE)
list(web_traffic_stream)

['186.99.192.116\tpython.org',
 '202.152.82.171\twikipedia.org',
 '130.126.231.205\tpython.org',
 '116.142.112.214\tpandas.pydata.org',
 '113.124.204.127\tpython.org',
 '143.30.183.87\twikipedia.org',
 '138.74.228.219\tpython.org',
 '56.120.106.87\twikipedia.org',
 '189.119.55.225\twikipedia.org',
 '180.110.73.101\twikipedia.org']

## Data structures

In [12]:
import murmurhash3

unique_IP_count = 0
domain_IPs = dict()
IP_x = '186.99.192.116'
domain_y = 'python.org'

STREAM_SIZE = 100
for element in stream(STREAM_SIZE):
    element = element.split()
    IP = element[0]
    domain = element[1]
    

186.99.192.116 python.org
202.152.82.171 wikipedia.org
130.126.231.205 python.org
116.142.112.214 pandas.pydata.org
113.124.204.127 python.org
143.30.183.87 wikipedia.org
138.74.228.219 python.org
56.120.106.87 wikipedia.org
189.119.55.225 wikipedia.org
180.110.73.101 wikipedia.org
125.147.103.124 python.org
89.161.15.82 wikipedia.org
64.108.133.139 pandas.pydata.org
87.91.133.89 pandas.pydata.org
111.141.147.118 wikipedia.org
97.65.99.76 wikipedia.org
80.99.56.157 wikipedia.org
122.86.146.117 wikipedia.org
200.132.86.152 pandas.pydata.org
98.200.179.72 python.org
82.129.212.123 wikipedia.org
118.134.162.177 python.org
142.129.144.83 pandas.pydata.org
20.128.105.18 wikipedia.org
166.31.84.181 python.org
194.77.131.184 pandas.pydata.org
204.76.93.95 wikipedia.org
164.82.140.88 wikipedia.org
175.168.120.155 wikipedia.org
147.125.63.84 wikipedia.org
109.96.154.73 wikipedia.org
217.77.159.138 wikipedia.org
127.194.124.74 dtu.dk
135.112.123.187 wikipedia.org
183.99.127.119 wikipedia.org
91.

## Analysis