AMON: An Open Source Architecture for Online Monitoring, Statistical Analysis, and Forensics of Multi-Gigabit Streams

被引:14
|
作者
Kallitsis, Michael [1 ]
Stoev, Stilian A. [2 ]
Bhattacharya, Shrijita [2 ]
Michailidis, George [3 ]
机构
[1] Merit Network Inc, Ann Arbor, MI 48104 USA
[2] Univ Michigan, Dept Stat, Ann Arbor, MI 48109 USA
[3] Univ Florida, Dept Stat, Gainesville, FL 32611 USA
基金
美国国家科学基金会;
关键词
Network monitoring; detection; identification; visualization; PF_RING; gigabit streams; commodity hardware; data products; algorithms; statistics; heavy tails; extreme value distribution; network attacks; FREQUENT;
D O I
10.1109/JSAC.2016.2558958
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Internet, as a global system of interconnected networks, carries an extensive array of information resources and services. Key requirements include good quality-of-service and protection of the infrastructure from nefarious activity [e.g., distributed denial of service (DDoS) attacks]. Network monitoring is essential to network engineering, capacity planning, and prevention/mitigation of threats. We develop an open-source architecture, All-packet MONitor (AMON), for online monitoring and analysis of multi-gigabit network streams. It leverages the high-performance packet monitor PF_RING and is readily deployable on commodity hardware. AMON examines all packets, partitions traffic into sub-streams by using rapid hashing and computes certain real-time data products. The resulting data structures provide views of the intensity and connectivity structure of network traffic at the time-scale of routing. The proposed integrated framework includes modules for the identification of heavy-hitters as well as for visualization and statistical detection at the time-of-onset of high-impact events such as DDoS. This allows operators to quickly visualize and diagnose attacks, and limit offline and time-consuming post-mortem analysis. We demonstrate our system in the context of real-world attack incidents, and validate it against state-of-the-art alternatives. AMON has been deployed and is currently processing multi-gigabit live Internet traffic at Merit Network. It is extensible and allows the addition of further statistical and filtering modules for real-time forensics.
引用
收藏
页码:1834 / 1848
页数:15
相关论文
共 5 条
  • [1] A network processor-based architecture for multi-gigabit traffic analysis
    Di Pietro, A.
    Ficara, D.
    Giordano, S.
    Oppedisano, F.
    Procissi, G.
    Vitucci, F.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2009, 22 (11) : 1403 - 1425
  • [2] XGT4: an Industrial Grade, Open Source Tester for Multi-Gigabit Networks
    Juracy, Leonardo R.
    Lazzarotto, Felipe B.
    Pigatto, Daniel
    Calazans, Ney L. V.
    Moraes, Fernando G.
    2017 24TH IEEE INTERNATIONAL CONFERENCE ON ELECTRONICS, CIRCUITS AND SYSTEMS (ICECS), 2017, : 252 - 255
  • [3] MIDAS: Open-source framework for distributed online analysis of data streams
    Henelius, Andreas
    Torniainen, Jar
    SOFTWAREX, 2018, 7 : 156 - 161
  • [4] Paleomagnetism.org: An online multi-platform open source environment for paleomagnetic data analysis
    Koymans, Mathijs R.
    Langereis, Cor G.
    Pastor-Galan, Daniel
    van Hinsbergen, Douwe J. J.
    COMPUTERS & GEOSCIENCES, 2016, 93 : 127 - 137
  • [5] Monitoring and Analysis of the Collapse at Xinjing Open-Pit Mine, Inner Mongolia, China, Using Multi-Source Remote Sensing
    Zhang, Nianbin
    Wang, Yunjia
    Zhao, Feng
    Wang, Teng
    Zhang, Kewei
    Fan, Hongdong
    Zhou, Dawei
    Zhang, Leixin
    Yan, Shiyong
    Diao, Xinpeng
    Song, Rui
    REMOTE SENSING, 2024, 16 (06)