Real time distributed analysis of MPLS network logs for anomaly detection

Muhammet Macit, Emrullah Delibaş, Bahtiyar Karanlik, Alperen Inal, Tevfik Aytekin

Araştırma sonucu: Kitap/Rapor/Konferans sürecindeki bölümKonferans katkısıbilirkişi

3 Alıntılar (Scopus)

Özet

Large scale IP networks contain thousands of network devices such as routers and switches. Massive amounts of logging data is generated by these devices. Analysing this data is both a challenge and an opportunity for finding network problems. Moreover, large IP networks contain devices from different vendors, so it is important to build a system which can work with network devices of different brands. In this study we describe a distributed architecture which can retrieve, store, and process massive amounts of network logging data in real time. Using this architecture we also build a basic anomaly detection system. The system statistically models cumulative counts of logs for different event types for all the devices in the network. The statistical approach lets the system to detect deviations from the normal behaviour without consulting expert knowledge. Our evaluations show that the system effectively handles massive amounts of data and detects anomalies.

Orijinal dilİngilizce
Ana bilgisayar yayını başlığıProceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
EditörlerSema Oktug Badonnel, Mehmet Ulema, Cicek Cavdar, Lisandro Zambenedetti Granville, Carlos Raniery P. dos Santos
YayınlayanInstitute of Electrical and Electronics Engineers Inc.
Sayfalar750-753
Sayfa sayısı4
ISBN (Elektronik)9781509002238
DOI'lar
Yayın durumuYayınlanan - 30 Haz 2016
Etkinlik2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016 - Istanbul, Turkey
Süre: 25 Nis 201629 Nis 2016

Yayın serisi

AdıProceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium

???event.eventtypes.event.conference???

???event.eventtypes.event.conference???2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016
Ülke/BölgeTurkey
ŞehirIstanbul
Periyot25/04/1629/04/16

Parmak izi

Real time distributed analysis of MPLS network logs for anomaly detection' araştırma başlıklarına git. Birlikte benzersiz bir parmak izi oluştururlar.

Bundan alıntı yap