A new connection degree calculation and measurement method for large scale network monitoring

被引:12
|
作者
Qin, Tao [1 ]
Guan, Xiaohong [1 ,2 ,3 ]
Li, Wei [1 ]
Wang, Pinghui [1 ]
Zhu, Min [1 ]
机构
[1] Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Shaanxi, Peoples R China
[2] Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
[3] Tsinghua Univ, TNLIST Lab, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
Abnormal behavior detection; Bi-directional flow; Degree correlation analysis; Renyi entropy; Reversible degree sketch;
D O I
10.1016/j.jnca.2013.10.008
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traffic pattern characteristics monitoring is useful for abnormal behavior detection and network management. In this paper, we develop a framework for connection degree calculation and measurement in high-speed networks. The bi-directional traffic flow model is employed to aggregate traffic packets, which can reduce the number of flow records and capture user's alternation behavior characteristics. The first order connection degree and joint correlation degree are selected as the features to capture the characteristics of traffic profiles. To perform careful traffic inspection and attack detection, not only the abnormal changes of a single traffic feature but also the correlations between the features are analyzed in the new framework. First, the symmetry of in and out connection degrees is analyzed. And we found that incomplete flows are an important information source for abnormal behavior detection. Second, joint correlation degree can characterize the user's communication profiles and their behavior dynamics, which are employed to perform abnormal detection using measurements based on Renyi cross entropy. Finally, the reversible degree sketch is employed for querying abnormal traffic pattern sources for real-time traffic management. The experimental results based on actual traffic traces collected from Northwest Regional Center of CERNET (China Education and Research Network) show the efficiency of the proposed method. The method based on Renyi entropy can detect abnormal changing points correctly. FNR of the reversible sketch for locating abnormal sources is below 4% and time complexity is constant and less than 4 s, which is critical for real-time traffic monitoring. Crown Copyright (c) 2013 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:15 / 26
页数:12
相关论文
共 50 条
  • [1] Characteristic Measurement of the Connection Degree for Network Monitoring
    Qin, Tao
    Guan, Xiaohong
    Huang, Qiuzhen
    Li, Wei
    2010 8TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION (WCICA), 2010, : 147 - 151
  • [2] A New Data Streaming Method for Locating Hosts with Large Connection Degree
    Guan, Xiaohong
    Wang, Pinghui
    Qin, Tao
    GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 6421 - 6426
  • [3] Calculation method for optimal measuring interval of large-scale straightness measurement
    Wang H.
    Shao Z.
    Fu Y.
    Han Z.
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2017, 23 (01): : 10 - 16
  • [4] Dynamic Feature Analysis and Measurement for Large-Scale Network Traffic Monitoring
    Guan, Xiaohong
    Qin, Tao
    Li, Wei
    Wang, Pinghui
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2010, 5 (04) : 905 - 919
  • [5] New method for hybrid decomposition of the large-scale network
    Huazhong Ligong Daxue Xuebao, 8 (125):
  • [6] New method for large-scale heat exchanger network synthesis
    Brandt, Christopher
    Fieg, Georg
    Luo, Xing
    Engel, Ole
    11TH INTERNATIONAL SYMPOSIUM ON PROCESS SYSTEMS ENGINEERING, PTS A AND B, 2012, 31 : 695 - 699
  • [7] A New Sketch Method for Measuring Host Connection Degree Distribution
    Wang, Pinghui
    Guan, Xiaohong
    Zhao, Junzhou
    Tao, Jing
    Qin, Tao
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (06) : 948 - 960
  • [8] A new calculation method for membership degree and non-membership degree of PFS
    Zhang, Qiang
    Chen, Guoming
    Yan, Qiming
    PROCEEDINGS OF THE 39TH CHINESE CONTROL CONFERENCE, 2020, : 6082 - 6085
  • [9] Combined measuring method in large scale measurement
    Wang, Shao-Feng
    Hong, Jun
    He, Qiao-Ling
    Yang, Yang
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2011, 17 (12): : 2638 - 2642
  • [10] Measurement method of inertia constant of power system based on large-scale wind power grid connection
    Sun, Feng
    Sun, Junjie
    Zhang, Xiaoheng
    Yang, Hongyu
    Qian, Xiaoyi
    Ye, Peng
    ENERGY REPORTS, 2022, 8 : 200 - 209