Dynamic Anomalography: Tracking Network Anomalies Via Sparsity and Low Rank

被引:91
作者
Mardani, Morteza [1 ,2 ]
Mateos, Gonzalo [1 ,2 ]
Giannakis, Georgios B. [1 ,2 ]
机构
[1] Univ Minnesota, Dept Elect & Comp Engn, Minneapolis, MN 55455 USA
[2] Univ Minnesota, Digital Technol Ctr, Minneapolis, MN 55455 USA
关键词
Traffic volume anomalies; online optimization; sparsity; network cartography; low rank;
D O I
10.1109/JSTSP.2012.2233193
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In the backbone of large-scale networks, origin-to-destination (OD) traffic flows experience abrupt unusual changes known as traffic volume anomalies, which can result in congestion and limit the extent to which end-user quality of service requirements are met. As a means of maintaining seamless end-user experience in dynamic environments, as well as for ensuring network security, this paper deals with a crucial network monitoring task termed dynamic anomalography. Given link traffic measurements (noisy superpositions of unobserved OD flows) periodically acquired by backbone routers, the goal is to construct an estimated map of anomalies in real time, and thus summarize the network 'health state' along both the flow and time dimensions. Leveraging the low intrinsic-dimensionality of OD flows and the sparse nature of anomalies, a novel online estimator is proposed based on an exponentially-weighted least-squares criterion regularized with the sparsity-promoting l(1)-norm of the anomalies, and the nuclear norm of the nominal traffic matrix. After recasting the non-separable nuclear norm into a form amenable to online optimization, a real-time algorithm for dynamic anomalography is developed and its convergence established under simplifying technical assumptions. For operational conditions where computational complexity reductions are at a premium, a lightweight stochastic gradient algorithm based on Nesterov's acceleration technique is developed as well. Comprehensive numerical tests with both synthetic and real network data corroborate the effectiveness of the proposed online algorithms and their tracking capabilities, and demonstrate that they outperform state-of-the-art approaches developed to diagnose traffic anomalies.
引用
收藏
页码:50 / 66
页数:17
相关论文
共 43 条
[31]  
Recht B., 2011, MATH PROGRAMM COMPUT
[32]   Guaranteed Minimum-Rank Solutions of Linear Matrix Equations via Nuclear Norm Minimization [J].
Recht, Benjamin ;
Fazel, Maryam ;
Parrilo, Pablo A. .
SIAM REVIEW, 2010, 52 (03) :471-501
[33]  
Rudin W., 1976, INT SERIES PURE APPL
[34]  
Sayed A. H., 2003, Fundamentals of Adaptive Filtering
[35]  
Solo V., 1995, Adaptive Signal Processing Algorithms: Stability and Performance
[36]   Anomaly detection in IP networks [J].
Thottan, M ;
Ji, C .
IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2003, 51 (08) :2191-2204
[37]   Just relax: Convex programming methods for identifying sparse signals in noise [J].
Tropp, JA .
IEEE TRANSACTIONS ON INFORMATION THEORY, 2006, 52 (03) :1030-1051
[38]   Convergence of a block coordinate descent method for nondifferentiable minimization [J].
Tseng, P .
JOURNAL OF OPTIMIZATION THEORY AND APPLICATIONS, 2001, 109 (03) :475-494
[39]  
Van der Vaart A. W., 2000, ASYMPTOTIC STAT, V3
[40]   PROJECTION APPROXIMATION SUBSPACE TRACKING [J].
YANG, B .
IEEE TRANSACTIONS ON SIGNAL PROCESSING, 1995, 43 (01) :95-107