Real time distributed analysis of MPLS network logs for anomaly detection
Real time distributed analysis of MPLS network logs for anomaly detection
复制标题
MPLS 网络日志的实时分布式分析以进行异常检测
DOI:
10.1109/noms.2016.7502891
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Tevfik Aytekin
中科院分区:
文献类型:
--
作者:
Muhammed Macit;Emrullah Delibas;Bahtiyar Karanlik;Alperen Inal;Tevfik Aytekin
Large scale IP networks contain thousands of network devices such as routers and switches. Massive amounts of logging data is generated by these devices. Analysing this data is both a challenge and an opportunity for finding network problems. Moreover, large IP networks contain devices from different vendors, so it is important to build a system which can work with network devices of different brands. In this study we describe a distributed architecture which can retrieve, store, and process massive amounts of network logging data in real time. Using this architecture we also build a basic anomaly detection system. The system statistically models cumulative counts of logs for different event types for all the devices in the network. The statistical approach lets the system to detect deviations from the normal behaviour without consulting expert knowledge. Our evaluations show that the system effectively handles massive amounts of data and detects anomalies.