• DocumentCode
    1667590
  • Title

    Real-time detection of hidden traffic patterns

  • Author

    Hao, Fang ; Kodialam, Murali ; Lakshman, T.V.

  • Author_Institution
    Lucent Technol., Bell Labs., Holmdel, NJ, USA
  • fYear
    2004
  • Firstpage
    340
  • Lastpage
    349
  • Abstract
    We address the problem of fast automatic identification of traffic patterns in core networks with high speed links carrying large numbers of flows. This problem has applications in detecting DoS attacks, traffic management, and network security. The typical measurement and identification objective is to determine flows that use up a disproportionate fraction of network resources. Several schemes have been devised to measure large flows efficiently assuming that the notion of what constitutes a flow is well defined a priori. However, there are many scenarios where traffic patterns are hidden in the sense that there is no clear knowledge of what exactly to look for and there is no natural a priori definition of flow. In This work, we develop an effective scheme to identify and measure hidden traffic patterns. The approach is flexible enough to automatically identify interesting traffic patterns for further evaluation. The basic idea is to extend the runs based approach proposed in (Kodialam, M. et al., 2004) to the case where flow definitions are not known a priori. A straightforward extension is both memory and processing intensive. We develop an efficient scheme that has good theoretical properties and does extremely well in practice.
  • Keywords
    pattern recognition; telecommunication links; telecommunication network management; telecommunication security; telecommunication traffic; core network; fast automatic identification; hidden traffic pattern; network security; real-time detection; traffic management; Computer crime; Engineering management; Fluid flow measurement; Monitoring; Particle measurements; Pricing; Protocols; Sampling methods; Statistics; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols, 2004. ICNP 2004. Proceedings of the 12th IEEE International Conference on
  • ISSN
    1092-1648
  • Print_ISBN
    0-7695-2161-4
  • Type

    conf

  • DOI
    10.1109/ICNP.2004.1348123
  • Filename
    1348123