Comparative Causal Analysis of Network Log Data in Two Large ISPs

被引:5
作者
Kobayashi, Satoru [1 ]
Shima, Keiichi [2 ]
Cho, Kenjiro [2 ]
Akashi, Osamu [1 ]
Fukuda, Kensuke [3 ]
机构
[1] NII, Tokyo, Japan
[2] IIJ, Tokyo, Japan
[3] NII Sokendai, Tokyo, Japan
来源
PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022 | 2022年
关键词
Network management; Log analysis; Causal discovery; Comparative analysis; ANOMALY DETECTION;
D O I
10.1109/NOMS54207.2022.9789823
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Towards a collaborative analysis of log data obtained from multiple networks, we first need to clarify what kind of information is available as transferable knowledge between different networks. However, we cannot directly compare network log data from different sources because the data largely depends on the network architecture and equipment. In this paper, we focus on relational information among network log events that follow standardized network protocols regardless of network environment. We propose a comparative analysis approach relying on causality between log time-series. In this approach, we classify log messages into anonymized log time-series with log templates, reduce the number of log time-series to decrease processing time, and apply causal discovery with the PC algorithm. To decrease the processing time of causal analysis, we propose a new preprocessing method that reduces the number of log time-series without any domain knowledge (i.e., available in any ISPs). We compare log data obtained from two nationwide ISPs to demonstrate the effectiveness of the causal approach in comparative analysis.
引用
收藏
页数:6
相关论文
共 21 条
[21]  
Zheng Z., 2012, PROC 9 INT C AUTONOM, P181