Real time distributed analysis of MPLS network logs for anomaly detection

Real time distributed analysis of MPLS network logs for anomaly detection
复制标题

MPLS 网络日志的实时分布式分析以进行异常检测

DOI:
10.1109/noms.2016.7502891
复制
发表时间:
2016
期刊:
IEEE/IFIP Network Operations and Management Symposium
影响因子:
--
通讯作者:
Tevfik Aytekin
Tevfik Aytekin
中科院分区:
--
文献类型:
--
作者:
Muhammed Macit;Emrullah Delibas;Bahtiyar Karanlik;Alperen Inal;Tevfik Aytekin

文献摘要

被引文献

相似文献

大规模的IP网络包含数以千计的网络设备,如路由器和交换机。这些设备产生了大量的记录数据。分析这些数据既是发现网络问题的挑战,也是发现问题的机会。此外,大型IP网络包含来自不同供应商的设备,因此构建一个可以与不同品牌的网络设备兼容的系统非常重要。在本研究中,我们描述了一个能够实时检索、存储和处理海量网络日志数据的分布式体系结构。利用该体系结构,我们还构建了一个基本的异常检测系统。系统对网络中所有设备的不同事件类型的累计日志计数进行统计建模。统计方法使系统能够在不咨询专家知识的情况下检测与正常行为的偏差。我们的评估表明,该系统有效地处理了海量数据并检测到异常。
Large scale IP networks contain thousands of network devices such as routers and switches. Massive amounts of logging data is generated by these devices. Analysing this data is both a challenge and an opportunity for finding network problems. Moreover, large IP networks contain devices from different vendors, so it is important to build a system which can work with network devices of different brands. In this study we describe a distributed architecture which can retrieve, store, and process massive amounts of network logging data in real time. Using this architecture we also build a basic anomaly detection system. The system statistically models cumulative counts of logs for different event types for all the devices in the network. The statistical approach lets the system to detect deviations from the normal behaviour without consulting expert knowledge. Our evaluations show that the system effectively handles massive amounts of data and detects anomalies.