Multivariate network traffic analysis using clustered patterns

被引:12
作者
Kim, Jinoh [1 ]
Sim, Alex [2 ]
Tierney, Brian [3 ]
Suh, Sang [1 ]
Kim, Ikkyun [4 ]
机构
[1] Texas A&M Univ, Commerce, TX 75428 USA
[2] Lawrence Berkeley Natl Lab, Berkeley, CA 94720 USA
[3] ESnet, Berkeley, CA 94720 USA
[4] ETRI, Daejeon 305700, South Korea
关键词
Network traffic analysis; Clustered patterns; Change detection; Anomaly detection; Multivariate analysis;
D O I
10.1007/s00607-018-0619-4
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Traffic analysis is a core element in network operations and management for various purposes including change detection, traffic prediction, and anomaly detection. In this paper, we introduce a new approach to online traffic analysis based on a pattern-based representation for high-level summarization of the traffic measurement data. Unlike the past online analysis techniques limited to a single variable to summarize (e.g., sketch), the focus of this study is on capturing the network state from the multivariate attributes under consideration. To this end, we employ clustering with its benefit of the aggregation of multidimensional variables. The clustered result represents the state of the network with regard to the monitored variables, which can also be compared with the observed patterns from previous time windows enabling intuitive analysis. We demonstrate the proposed method with two popular use cases, one for estimating state changes and the other for identifying anomalous states, to confirm its feasibility. Our extensive experimental results with public traces and collected monitoring measurements from ESnet traffic traces show that our pattern-based approach is effective for multivariate analysis of online network traffic with visual and quantitative tools.
引用
收藏
页码:339 / 361
页数:23
相关论文
共 37 条
  • [1] A survey of network anomaly detection techniques
    Ahmed, Mohiuddin
    Mahmood, Abdun Naser
    Hu, Jiankun
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 60 : 19 - 31
  • [2] [Anonymous], 2007, TECHNICAL REPORT
  • [3] [Anonymous], 2015, P INT WORKSH SEC PRI, DOI DOI 10.1145/2713579.2713583
  • [4] [Anonymous], 2013, LBNL6341E
  • [5] [Anonymous], P SC13 INT C HIGH PE
  • [6] Scalable K-Means++
    Bahmani, Bahman
    Moseley, Benjamin
    Vattani, Andrea
    Kumar, Ravi
    Vassilvitskii, Sergei
    [J]. PROCEEDINGS OF THE VLDB ENDOWMENT, 2012, 5 (07): : 622 - 633
  • [7] Balachander K., 2003, ACM IMC, P234
  • [8] Cho K, 2008, P 2008 ACM C EM NETW, P12
  • [9] CoTS: A Scalable Framework for Parallelizing Frequency Counting over Data Streams
    Das, Sudipto
    Antony, Shyam
    Agrawal, Divyakant
    El Abbadi, Amr
    [J]. ICDE: 2009 IEEE 25TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING, VOLS 1-3, 2009, : 1323 - 1326
  • [10] Datar M, 2002, SIAM PROC S, P635