A new connection degree calculation and measurement method for large scale network monitoring

被引:12
|
作者
Qin, Tao [1 ]
Guan, Xiaohong [1 ,2 ,3 ]
Li, Wei [1 ]
Wang, Pinghui [1 ]
Zhu, Min [1 ]
机构
[1] Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Shaanxi, Peoples R China
[2] Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
[3] Tsinghua Univ, TNLIST Lab, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
Abnormal behavior detection; Bi-directional flow; Degree correlation analysis; Renyi entropy; Reversible degree sketch;
D O I
10.1016/j.jnca.2013.10.008
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traffic pattern characteristics monitoring is useful for abnormal behavior detection and network management. In this paper, we develop a framework for connection degree calculation and measurement in high-speed networks. The bi-directional traffic flow model is employed to aggregate traffic packets, which can reduce the number of flow records and capture user's alternation behavior characteristics. The first order connection degree and joint correlation degree are selected as the features to capture the characteristics of traffic profiles. To perform careful traffic inspection and attack detection, not only the abnormal changes of a single traffic feature but also the correlations between the features are analyzed in the new framework. First, the symmetry of in and out connection degrees is analyzed. And we found that incomplete flows are an important information source for abnormal behavior detection. Second, joint correlation degree can characterize the user's communication profiles and their behavior dynamics, which are employed to perform abnormal detection using measurements based on Renyi cross entropy. Finally, the reversible degree sketch is employed for querying abnormal traffic pattern sources for real-time traffic management. The experimental results based on actual traffic traces collected from Northwest Regional Center of CERNET (China Education and Research Network) show the efficiency of the proposed method. The method based on Renyi entropy can detect abnormal changing points correctly. FNR of the reversible sketch for locating abnormal sources is below 4% and time complexity is constant and less than 4 s, which is critical for real-time traffic monitoring. Crown Copyright (c) 2013 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:15 / 26
页数:12
相关论文
共 50 条
  • [21] A reconfigurable monitoring system for large-scale network computing
    Subramanyan, R
    Miguel-Alonso, J
    Fortes, JAB
    EURO-PAR 2003 PARALLEL PROCESSING, PROCEEDINGS, 2003, 2790 : 98 - 108
  • [22] Study on Method of Resistance Measurement Aimed at Ventilation Network Calculation
    Wu Fengliang
    Wang Honggang
    Zhang Jianrang
    PROGRESS IN SAFETY SCIENCE AND TECHNOLOGY, VOL VII, PTS A AND B, 2008, 7 : 1716 - 1719
  • [23] A new measurement technique for monitoring inorganic scale deposition
    Cruz, Arley Alles
    Dossi, Fabio Cleisto Alda
    Salazar-Banda, Giancarlo Richard
    Franceschi, Elton
    Borges, Gustavo Rodrigues
    Dariva, Claudio
    JOURNAL OF THE BRAZILIAN SOCIETY OF MECHANICAL SCIENCES AND ENGINEERING, 2023, 45 (08)
  • [24] A new measurement technique for monitoring inorganic scale deposition
    Arley Alles Cruz
    Fabio Cleisto Alda Dossi
    Giancarlo Richard Salazar-Banda
    Elton Franceschi
    Gustavo Rodrigues Borges
    Claudio Dariva
    Journal of the Brazilian Society of Mechanical Sciences and Engineering, 2023, 45
  • [25] High-Speed Calculation Method for Large-Scale Multi-Layer Network Design Problem
    Mikoshi, Taiju
    Takenaka, Toyofumi
    Sugiyama, Ryuta
    Masuda, Akeo
    Shiomoto, Kohei
    Hiramatsu, Atsushi
    2012 15TH INTERNATIONAL TELECOMMUNICATIONS NETWORK STRATEGY AND PLANNING SYMPOSIUM (NETWORKS), 2012,
  • [26] Distributed measurement policy protocol for large-scale network
    Zhang, GM
    Xing, CY
    Chen, M
    International Symposium on Communications and Information Technologies 2005, Vols 1 and 2, Proceedings, 2005, : 30 - 33
  • [27] NetQuest: A Flexible Framework for Large-Scale Network Measurement
    Song, Han Hee
    Qiu, Lili
    Zhang, Yin
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2009, 17 (01) : 106 - 119
  • [28] A heuristic scheduling method for a large scale distribution network
    Li, Bo
    Tang, Zhizhong
    Zhu, Lin
    Journal of Information and Computational Science, 2015, 12 (13): : 4983 - 4992
  • [29] Nodes clustering method in large-scale network
    Ju Hong-Jun
    Du Li-Juan
    2012 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING (WICOM), 2012,
  • [30] Degree-biased random walk for large-scale network embedding
    Zhang, Yunyi
    Shi, Zhan
    Feng, Dan
    Zhan, Xiu-Xiu
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 100 : 198 - 209