TY - GEN
T1 - Detectability of traffic anomalies in two adjacent networks
AU - Soule, Augustin
AU - Ringberg, Haakon
AU - Silveira, Fernando
AU - Rexford, Jennifer L.
AU - Diot, Christophe
PY - 2007
Y1 - 2007
N2 - Anomaly detection remains a poorly understood area where visual inspection and manual analysis play a significant role in the effectiveness of the detection technique. We observe traffic anomalies in two adjacent networks, namely GEANT and Abilene, in order to determine what parameters impact the detectability and the characteristics of anomalies. We correlate three weeks of traffic and routing data from both networks and apply Kalman filtering to detect anomalies that transit between the two networks. We show that differences in the monitoring infrastructure, network engineering practices, and anomaly-detection parameters have a large impact on which anomaly detectability. Through a case study of three specific anomalies, we illustrate the influence of the traffic mix, IP address anonymization, detection methodology, and packet sampling on the detectability of traffic anomalies.
AB - Anomaly detection remains a poorly understood area where visual inspection and manual analysis play a significant role in the effectiveness of the detection technique. We observe traffic anomalies in two adjacent networks, namely GEANT and Abilene, in order to determine what parameters impact the detectability and the characteristics of anomalies. We correlate three weeks of traffic and routing data from both networks and apply Kalman filtering to detect anomalies that transit between the two networks. We show that differences in the monitoring infrastructure, network engineering practices, and anomaly-detection parameters have a large impact on which anomaly detectability. Through a case study of three specific anomalies, we illustrate the influence of the traffic mix, IP address anonymization, detection methodology, and packet sampling on the detectability of traffic anomalies.
UR - http://www.scopus.com/inward/record.url?scp=38049112999&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=38049112999&partnerID=8YFLogxK
U2 - 10.1007/978-3-540-71617-4_3
DO - 10.1007/978-3-540-71617-4_3
M3 - Conference contribution
AN - SCOPUS:38049112999
SN - 9783540716167
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 22
EP - 31
BT - Passive and Active Network Measurement - 8th International Conference, PAM 2007, Proceedings
PB - Springer Verlag
T2 - 8th International Passive and Active Measurement Conference, PAM 2007
Y2 - 5 April 2007 through 6 April 2007
ER -