A new connection degree calculation and measurement method for large scale network monitoring

被引:12
|
作者
Qin, Tao [1 ]
Guan, Xiaohong [1 ,2 ,3 ]
Li, Wei [1 ]
Wang, Pinghui [1 ]
Zhu, Min [1 ]
机构
[1] Xi An Jiao Tong Univ, MOE KLINNS Lab, Xian 710049, Shaanxi, Peoples R China
[2] Tsinghua Univ, Dept Automat, Beijing 100084, Peoples R China
[3] Tsinghua Univ, TNLIST Lab, Beijing 100084, Peoples R China
基金
中国国家自然科学基金;
关键词
Abnormal behavior detection; Bi-directional flow; Degree correlation analysis; Renyi entropy; Reversible degree sketch;
D O I
10.1016/j.jnca.2013.10.008
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Traffic pattern characteristics monitoring is useful for abnormal behavior detection and network management. In this paper, we develop a framework for connection degree calculation and measurement in high-speed networks. The bi-directional traffic flow model is employed to aggregate traffic packets, which can reduce the number of flow records and capture user's alternation behavior characteristics. The first order connection degree and joint correlation degree are selected as the features to capture the characteristics of traffic profiles. To perform careful traffic inspection and attack detection, not only the abnormal changes of a single traffic feature but also the correlations between the features are analyzed in the new framework. First, the symmetry of in and out connection degrees is analyzed. And we found that incomplete flows are an important information source for abnormal behavior detection. Second, joint correlation degree can characterize the user's communication profiles and their behavior dynamics, which are employed to perform abnormal detection using measurements based on Renyi cross entropy. Finally, the reversible degree sketch is employed for querying abnormal traffic pattern sources for real-time traffic management. The experimental results based on actual traffic traces collected from Northwest Regional Center of CERNET (China Education and Research Network) show the efficiency of the proposed method. The method based on Renyi entropy can detect abnormal changing points correctly. FNR of the reversible sketch for locating abnormal sources is below 4% and time complexity is constant and less than 4 s, which is critical for real-time traffic monitoring. Crown Copyright (c) 2013 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:15 / 26
页数:12
相关论文
共 50 条
  • [41] Study of Large Scale Measurement Method Based on Leapfrog Principle
    Zheng, LongJiang
    Li, Xue
    Qin, LingLing
    Chen, HongBin
    Gao, Xue
    Yuan, RuiRong
    MECHANICAL AND ELECTRONICS ENGINEERING III, PTS 1-5, 2012, 130-134 : 1560 - 1563
  • [42] A novel accuracy evaluation method for large scale vision measurement
    Yang, J.
    Lu, N.
    Dong, M.
    Yan, B.
    Wang, J.
    JOURNAL OF OPTOELECTRONICS AND ADVANCED MATERIALS, 2009, 11 (11): : 1675 - 1680
  • [43] A method of precision evaluation for field large-scale measurement
    Zhang, Fumin
    Qu, Xinghua
    Dai, Jianfang
    Ye, Shenghua
    Guangxue Xuebao/Acta Optica Sinica, 2008, 28 (11): : 2159 - 2163
  • [44] The study of a method for measurement of roundness of large-scale workpiece
    Ma, XL
    Yuan, CL
    ISTM/97 - 2ND INTERNATIONAL SYMPOSIUM ON TEST AND MEASUREMENT, CONFERENCE PROCEEDINGS, 1997, : 500 - 503
  • [45] Large-scale automated forecasting for network safety and security monitoring
    Naveiro, Roi
    Rodriguez, Simon
    Rios Insua, David
    APPLIED STOCHASTIC MODELS IN BUSINESS AND INDUSTRY, 2019, 35 (03) : 431 - 447
  • [46] Paralleling temperature monitoring in large scale sensor network with energy constrains
    Hu, Hua
    PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 2667 - 2672
  • [47] Transmission line fault-cause identification method for large-scale new energy grid connection scenarios
    Liang, Hanqing
    Han, Xiaonan
    Yu, Haoyang
    Li, Fan
    Liu, Zhongjian
    Zhang, Kexin
    GLOBAL ENERGY INTERCONNECTION-CHINA, 2022, 5 (04): : 362 - 374
  • [48] Nebav: A Visualization Tool for Monitoring Large-scale Network Behaviors
    Li, Tao
    Gong, Jian
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON INFORMATION, ELECTRONIC AND COMPUTER SCIENCE, VOLS I AND II, 2009, : 139 - 142
  • [49] Optimization of a large-scale microseismic monitoring network in northern Switzerland
    Kraft, Toni
    Mignan, Arnaud
    Giardini, Domenico
    GEOPHYSICAL JOURNAL INTERNATIONAL, 2013, 195 (01) : 474 - 490
  • [50] Transmission line fault-cause identification method for large-scale new energy grid connection scenarios
    Hanqing Liang
    Xiaonan Han
    Haoyang Yu
    Fan Li
    Zhongjian Liu
    Kexin Zhang
    GlobalEnergyInterconnection, 2022, 5 (04) : 362 - 374