Anomaly Detection and Root Cause Localization in Virtual Network Functions

被引:59
作者
Sauvanaud, Carla [1 ]
Lazri, Kahina [2 ]
Kaaniche, Mohamed [1 ]
Kanoun, Karama [1 ]
机构
[1] Univ Toulouse, CNRS, LAAS CNRS, Toulouse, France
[2] Orange Labs, 38 Rue Gen Leclerc, F-92130 Issy Les Moulineax, France
来源
2016 IEEE 27TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE) | 2016年
关键词
Anomaly detection; VNF; monitoring data; machine learning; fault injection; SLA; root cause analysis; RANDOM-FORESTS;
D O I
10.1109/ISSRE.2016.32
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The maturity of hardware virtualization has motivated Communication Service Providers (CSPs) to apply this paradigm to network services. Virtual Network Functions (VNFs) result from this trend and raise new dependability challenges related to network softwarisation that are still not thoroughly explored. This paper describes a new approach to detect Service Level Agreements (SLAs) violations and preliminary symptoms of SLAs violations. In particular, one other major objective of our approach is to help CSP administrators to identify the anomalous VM at the origin of the detected SLA violation, which should enable them to proactively plan for appropriate recovery strategies. To this end, we make use of virtual machine (VM) monitoring data and perform both a per-VM and an ensemble analysis. Our approach includes a supervised machine learning algorithm as well as fault injection tools. The experimental testbed consists of a virtual IP Multimedia Subsystem developed by the Clearwater project. Experimental results show that our approach can achieve high precision and recall, and low false alarm rate and can pinpoint the root anomalous VNF VM causing SLA violations. It can also detect preliminary symptoms of high workloads triggering SLA violations.
引用
收藏
页码:196 / 206
页数:11
相关论文
共 33 条
[11]   AN INTRUSION-DETECTION MODEL [J].
DENNING, DE .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 1987, 13 (02) :222-232
[12]  
ETSI, 2012, 103125 ETSI
[13]   OpenANFV: Accelerating Network Function Virtualization with a Consolidated Framework in Open Stack [J].
Ge, Xiongzi ;
Liu, Yi ;
Du, David H. C. ;
Zhang, Liang ;
Guan, Hongguang ;
Chen, Jian ;
Zhao, Yuping ;
Hu, Xinyu .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) :353-354
[14]   Adaptive Anomaly Identification by Exploring Metric Subspace in Cloud Computing Infrastructures [J].
Guan, Qiang ;
Fu, Song .
2013 IEEE 32ND INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS 2013), 2013, :205-214
[15]  
Heberlein LT, 1995, NETWORK SECURITY MON
[16]   FChain: Toward Black-box Online Fault Localization for Cloud Systems [J].
Hiep Nguyen ;
Shen, Zhiming ;
Tan, Yongmin ;
Gu, Xiaohui .
2013 IEEE 33RD INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2013, :21-30
[17]  
Kang H., 2012, 2 USENIX WORKSH HOT
[18]  
Kang H., 2010, P 7 INT C AUTONOMIC, P119, DOI [10.1145/1809049.1809070, DOI 10.1145/1809049.1809070]
[19]  
Kawakami K, 2012, 2012 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), P418, DOI 10.1109/ICCE.2012.6161956
[20]   Software-Defined Networking: A Comprehensive Survey [J].
Kreutz, Diego ;
Ramos, Fernando M. V. ;
Verissimo, Paulo Esteves ;
Rothenberg, Christian Esteve ;
Azodolmolky, Siamak ;
Uhlig, Steve .
PROCEEDINGS OF THE IEEE, 2015, 103 (01) :14-76