A new connection degree calculation and measurement method for large scale network monitoring

被引:12
|
作者
Qin, Tao [1 ]
Guan, Xiaohong [1 ,2 ,3 ]
Li, Wei [1 ]
Wang, Pinghui [1 ]
Zhu, Min [1 ]
机构
[1] Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Shaanxi, Peoples R China
[2] Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
[3] Tsinghua Univ, TNLIST Lab, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
Abnormal behavior detection; Bi-directional flow; Degree correlation analysis; Renyi entropy; Reversible degree sketch;
D O I
10.1016/j.jnca.2013.10.008
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traffic pattern characteristics monitoring is useful for abnormal behavior detection and network management. In this paper, we develop a framework for connection degree calculation and measurement in high-speed networks. The bi-directional traffic flow model is employed to aggregate traffic packets, which can reduce the number of flow records and capture user's alternation behavior characteristics. The first order connection degree and joint correlation degree are selected as the features to capture the characteristics of traffic profiles. To perform careful traffic inspection and attack detection, not only the abnormal changes of a single traffic feature but also the correlations between the features are analyzed in the new framework. First, the symmetry of in and out connection degrees is analyzed. And we found that incomplete flows are an important information source for abnormal behavior detection. Second, joint correlation degree can characterize the user's communication profiles and their behavior dynamics, which are employed to perform abnormal detection using measurements based on Renyi cross entropy. Finally, the reversible degree sketch is employed for querying abnormal traffic pattern sources for real-time traffic management. The experimental results based on actual traffic traces collected from Northwest Regional Center of CERNET (China Education and Research Network) show the efficiency of the proposed method. The method based on Renyi entropy can detect abnormal changing points correctly. FNR of the reversible sketch for locating abnormal sources is below 4% and time complexity is constant and less than 4 s, which is critical for real-time traffic monitoring. Crown Copyright (c) 2013 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:15 / 26
页数:12
相关论文
共 50 条
  • [31] A network reduction method inducing scale-free degree distribution
    Martin, Nicolas
    Frasca, Paolo
    Canudas-de-Wit, Carlos
    2018 EUROPEAN CONTROL CONFERENCE (ECC), 2018, : 2236 - 2241
  • [32] A NEW METHOD FOR CALCULATION OF LARGE NUMBERS OF TERMINAL VELOCITIES
    ALSALIM, QAW
    GELDART, D
    POWDER TECHNOLOGY, 1970, 3 (04) : 251 - &
  • [33] Calculation Method of Success Rate for Idling Grid-connection of Large Synchronous Condensers
    Yang H.
    Zheng Y.
    Wang X.
    Jian Y.
    Hu J.
    Yang, Hemin (yanghemin@sgepri.sgcc.com.cn), 2018, Automation of Electric Power Systems Press (42): : 74 - 78
  • [34] Measurement platform for structural health monitoring application of large scale structures
    Lambinet, F.
    Khodaei, Z. Sharif
    MEASUREMENT, 2022, 190
  • [35] A new five degree-of-freedom measurement method and system
    You, Fengling
    Feng, Qibo
    Zhang, Bin
    2008 INTERNATIONAL CONFERENCE ON OPTICAL INSTRUMENTS AND TECHNOLOGY: OPTICAL SYSTEMS AND OPTOELECTRONIC INSTRUMENTS, 2009, 7156
  • [36] A model reduction method for monitoring large-scale processes
    Kruger, U
    Wang, X
    Qin, SJ
    NEW TECHNOLOGIES FOR COMPUTER CONTROL 2001, 2002, : 395 - 400
  • [37] New network topologies for large scale Photovoltaic Systems
    Carcangiu, G.
    Dainese, C.
    Faranda, R.
    Leva, S.
    Sardo, M.
    2009 IEEE BUCHAREST POWERTECH, VOLS 1-5, 2009, : 1846 - +
  • [38] Optimizing the freight train connection service network of a large-scale rail system
    Lin, Bo-Liang
    Wang, Zhi-Mei
    Ji, Li-Jun
    Tian, Ya-Ming
    Zhou, Guo-Qing
    TRANSPORTATION RESEARCH PART B-METHODOLOGICAL, 2012, 46 (05) : 649 - 667
  • [39] Performance Analysis and Improvement of Newton Method for Power Flow Calculation of Large-scale Integrated Transmission and Distribution Network
    Tang K.
    Dong S.
    Zhu B.
    Song Y.
    Dianli Xitong Zidonghua/Automation of Electric Power Systems, 2019, 43 (06): : 92 - 99
  • [40] On-line monitoring method of large-scale weapon equipment based on multilayer competition neural network
    Zhou Zhaofa
    Huang Xianxiang
    Zhang Zhili
    ICEMI 2007: PROCEEDINGS OF 2007 8TH INTERNATIONAL CONFERENCE ON ELECTRONIC MEASUREMENT & INSTRUMENTS, VOL III, 2007, : 660 - +