Count Me In: Viable Distributed Summary Statistics for Securing High-Speed Networks

Count Me In: Viable Distributed Summary Statistics for Securing High-Speed Networks
复制标题

算我一个:用于保护高速网络的可行的分布式摘要统计

DOI:
--
复制
发表时间:
2014
期刊:
International Symposium on Recent Advances in Intrusion Detection
影响因子:
--
通讯作者:
Robin Sommer
Robin Sommer
中科院分区:
--
文献类型:
--
作者:
J. Amann;Seth Hall;Robin Sommer

文献摘要

被引文献

相似文献

摘要统计信息是分析和保护运营网络的关键原语。许多网络运营商经常测量吞吐量、流量组合和重量级用户等属性。同样,安全监视通常部署例如当源扫描本地IP地址范围或超过失败登录尝试的阈值时触发的统计异常检测器。传统上,这类计算使用一套不同的工具,每个工具通常都对其操作的特征或执行的特定计算进行硬编码,或两者兼而有之。在这项工作中,我们提出了一种新的框架,用于实时计算广泛的汇总统计数据,独立于底层数据,并可能从独立的监测点聚合。我们致力于提供透明、可扩展、易于使用的接口,并在开源网络监控系统的基础上实现我们的设计。我们演示了一组用于分析和统计异常检测的示例应用程序,这些应用程序传统上需要大量的工作和不同的工具来计算。我们已经在BSD许可下发布了我们的实施,并报告了在大规模网络环境中实际部署的经验。
Summary statistics represent a key primitive for profiling and protecting operational networks. Many network operators routinely measure properties such as throughput, traffic mix, and heavy hitters. Likewise, security monitoring often deploys statistical anomaly detectors that trigger, e.g., when a source scans the local IP address range, or exceeds a threshold of failed login attempts. Traditionally, a diverse set of tools is used for such computations, each typically hard-coding either the features it operates on or the specific calculations it performs, or both. In this work we present a novel framework for calculating a wide array of summary statistics in real-time, independent of the underlying data, and potentially aggregated from independent monitoring points. We focus on providing a transparent, extensible, easy-to-use interface and implement our design on top of an open-source network monitoring system. We demonstrate a set of example applications for profiling and statistical anomaly detection that would traditionally require significant effort and different tools to compute. We have released our implementation under BSD license and report experiences from real-world deployments in large-scale network environments.