Real-time behaviour profiling for network monitoring

被引:3
|
作者
Xu, Kuai [1 ]
Wang, Feng [1 ]
Bhattacharyya, Supratik [2 ]
Zhang, Zhi-Li [3 ]
机构
[1] Arizona State Univ, 4701 W Thunderbird Rd, Glendale, AZ 85306 USA
[2] SnapTell Inc, Palo Alto, CA 94306 USA
[3] Univ Minnesota, Dept Comp Sci & Engn, Minneapolis, MN 55416 USA
基金
美国国家科学基金会;
关键词
real-time traffic monitoring; behaviour profiling; profiling-aware filtering algorithms;
D O I
10.1504/IJIPT.2010.032616
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents the design and implementation of a real-time behaviour profiling system for internet links. The system uses flow-level information, and applies data mining and information-theoretic techniques to automatically discover significant events based on communication patterns. We demonstrate the operational feasibility of the system by implementing it and performing benchmarking of CPU and memory costs using packet traces from backbone links. To improve the robustness of this system against sudden traffic surges, we propose a novel filtering algorithm. The proposed algorithm successfully reduces the CPU and memory cost while maintaining high profiling accuracy. Finally, we devise and evaluate simple yet effective blocking strategies to reduce prevalent exploit traffic, and build a simple event analysis engine to generate ACL rules for filtering unwanted traffic.
引用
收藏
页码:65 / 80
页数:16
相关论文
共 50 条
  • [31] National Seismological Network in India for Real-Time Earthquake Monitoring
    Bansal, Brijesh K.
    Pandey, Ajeet P.
    Singh, Ajay P.
    Suresh, Gaddale
    Singh, Ravi K.
    Gautam, Jia L.
    [J]. SEISMOLOGICAL RESEARCH LETTERS, 2021, 92 (04) : 2255 - 2269
  • [32] Real-time nuclear power plant monitoring with neural network
    Nabeshima, K
    Suzudo, T
    Suzuki, K
    Turkcan, E
    [J]. JOURNAL OF NUCLEAR SCIENCE AND TECHNOLOGY, 1998, 35 (02) : 93 - 100
  • [33] An approach for real-time monitoring and control of tactical network simulations
    Stine, John A.
    Mirhakkak, Mohammad
    Schult, Nancy
    Schwartz, Jonathan
    [J]. 2007 IEEE MILITARY COMMUNICATIONS CONFERENCE, VOLS 1-8, 2007, : 2866 - 2871
  • [34] Wireless Sensor Network Testbed for Real-time Sensor Monitoring
    Hong, Sang Gi
    Moon, Young Bag
    Park, Sang Joon
    Kim, Whan Woo
    [J]. 2009 3RD INTERNATIONAL CONFERENCE ON SENSOR TECHNOLOGIES AND APPLICATIONS (SENSORCOMM 2009), 2009, : 486 - +
  • [35] The Implementation of Real-Time Network Traffic Monitoring Service with Network Functions Virtualization
    Yang, Yao-Yu
    Cheng, Wei-Hsun
    Yang, Chao-Tung
    Chen, Shuo-Tsung
    Jiang, Fuu-Cheng
    [J]. 2015 INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA (CCBD), 2015, : 279 - 286
  • [36] Implementation of a real-time network traffic monitoring service with network functions virtualization
    Yang, Chao-Tung
    Chen, Shuo-Tsung
    Liu, Jung-Chun
    Yang, Yao-Yu
    Mitra, Karan
    Ranjan, Rajiv
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 93 : 687 - 701
  • [37] Real-Time Berth Monitoring
    Mech, Konrad
    [J]. SEA TECHNOLOGY, 2019, 60 (03) : 15 - 17
  • [38] Real-time process monitoring
    Bunkofske, RJ
    Pascoe, NT
    Colt, JZ
    Smit, MW
    [J]. 1996 ADVANCED SEMICONDUCTOR MANUFACTURING CONFERENCE AND WORKSHOP - ASMC 96 PROCEEDINGS: THEME - INNOVATIVE APPROACHES TO GROWTH IN THE SEMICONDUCTOR INDUSTRY, 1996, : 382 - 390
  • [39] Real-time EGNOS Monitoring
    Pfleger, Michal
    Spacek, Josef
    [J]. PROCEEDINGS ELMAR-2010, 2010, : 425 - 428
  • [40] Real-time monitoring system
    不详
    [J]. ANTI-CORROSION METHODS AND MATERIALS, 1997, 44 (02) : 137 - 137