Count Me In: Viable Distributed Summary Statistics for Securing High-Speed Networks
Count Me In: Viable Distributed Summary Statistics for Securing High-Speed Networks
复制标题
算我一个:用于保护高速网络的可行的分布式摘要统计
DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Robin Sommer
中科院分区:
文献类型:
--
作者:
J. Amann;Seth Hall;Robin Sommer
Summary statistics represent a key primitive for profiling and protecting operational networks. Many network operators routinely measure properties such as throughput, traffic mix, and heavy hitters. Likewise, security monitoring often deploys statistical anomaly detectors that trigger, e.g., when a source scans the local IP address range, or exceeds a threshold of failed login attempts. Traditionally, a diverse set of tools is used for such computations, each typically hard-coding either the features it operates on or the specific calculations it performs, or both. In this work we present a novel framework for calculating a wide array of summary statistics in real-time, independent of the underlying data, and potentially aggregated from independent monitoring points. We focus on providing a transparent, extensible, easy-to-use interface and implement our design on top of an open-source network monitoring system. We demonstrate a set of example applications for profiling and statistical anomaly detection that would traditionally require significant effort and different tools to compute. We have released our implementation under BSD license and report experiences from real-world deployments in large-scale network environments.