DocumentCode :
3013186
Title :
NOMAD: traffic-based network monitoring framework for anomaly detection
Author :
Talpade, Rajesh ; Kim, Gitae ; Khurana, Sumit
Author_Institution :
Telcordia Technol., Morristown, NJ, USA
fYear :
1999
fDate :
1999
Firstpage :
442
Lastpage :
451
Abstract :
Network performance monitoring is essential for managing a network efficiently and for ensuring reliable operation of the network. In this paper we introduce a scalable network monitoring framework, (NOMAD), that detects network anomalies through the characterization of the dynamic statistical properties of network traffic. NOMAD relies on high resolution measurements and on-line analysis of network traffic to provide real-time alarms in the incipient phase of network anomalies. It incorporates a suite of anomaly identification algorithms based on path changes, flow shift, and packet delay variance, and relies extensively on IP packet header information, such as TTL, source/destination address and packet length, and router´s timestamps. NOMAD can be deployed in a single backbone router or incrementally in a regional or large scale network for detecting and locating network anomalies by correlating spatial and temporal network state information
Keywords :
computerised monitoring; packet switching; statistical analysis; telecommunication computing; telecommunication network management; telecommunication network routing; telecommunication traffic; IP packet header information; NOMAD; TTL; anomaly detection; anomaly identification algorithms; backbone router; dynamic statistical properties; flow shift; high resolution measurements; large scale network; network management; network traffic; on-line analysis; packet delay variance; packet length; real-time alarms; router timestamps; scalable network monitoring framework; source/destination address; traffic-based network monitoring framework; Aging; Computer network reliability; Computer science; Computerized monitoring; Delay; Large-scale systems; Next generation networking; Protocols; Spine; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computers and Communications, 1999. Proceedings. IEEE International Symposium on
Conference_Location :
Red Sea
Print_ISBN :
0-7695-0250-4
Type :
conf
DOI :
10.1109/ISCC.1999.780942
Filename :
780942
Link To Document :
بازگشت