Distributed Online Anomaly Detection for Virtualized Network Slicing Environment

Distributed Online Anomaly Detection for Virtualized Network Slicing Environment
复制标题

DOI:
10.1109/tvt.2022.3193074
复制
发表时间:
2022-01
影响因子:
6.8
通讯作者:
Weili Wang;C. Liang;Qianbin Chen;Lun Tang;H. Yanikomeroglu;Tong Liu
Weili Wang;C. Liang;Qianbin Chen;Lun Tang;H. Yanikomeroglu;Tong Liu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Weili Wang;C. Liang;Qianbin Chen;Lun Tang;H. Yanikomeroglu;Tong Liu

文献摘要

相似文献

由于网络切片是通信网络中的关键使能之一,承载多个虚拟网元的底层网络中一个异常的物理节点(PN)或物理链路(PL)会导致多个网络切片的性能显著下降。为了在短时间内从异常中恢复基底网络,快速准确地识别PNS和PLS中是否存在异常是至关重要的。首选能够实时分析系统数据的在线异常检测方法。此外,由于映射到PNS和PLS的虚拟节点和链路分散在多个切片中,因此需要分布式的检测模式来适应虚拟环境。针对这些需求,本文首先提出了一种基于分布式单类支持向量机(OCSVM)的分布式在线PN异常检测算法,该算法通过分布式分析映射到PNS的虚拟节点的实时测量值来实现。通过引入一致性约束,将原问题转化为一组分散的二次规划问题,实现了OCSVM目标函数的解耦。采用乘子交替方向法实现了分布式在线PN异常检测的解决方案。其次,利用相邻虚拟节点之间的量测相关性,提出了一种基于典型相关分析的分布式在线PL异常检测算法。该网络只需要存储当前数据的协方差矩阵和均值向量,就可以计算出典型的相关向量,用于实时分析PL异常。在模拟数据集和真实网络数据集上的仿真结果表明了所提出的分布式在线异常检测算法的有效性和稳健性。
As the network slicing is one of the critical enablers in communication networks, one anomalous physical node (PN) or physical link (PL) in substrate networks that carries multiple virtual network elements can cause significant performance degradation of multiple network slices. To recover the substrate networks from anomaly within a short time, rapid and accurate identification of whether or not the anomaly exists in PNs and PLs is vital. Online anomaly detection methods that can analyze system data in real-time are preferred. Besides, as virtual nodes and links mapped to PNs and PLs are scattered in multiple slices, the distributed detection modes are required to adapt to the virtualized environment. According to those requirements, in this paper, we first propose a distributed online PN anomaly detection algorithm based on a decentralized one-class support vector machine (OCSVM), which is realized through analyzing real-time measurements of virtual nodes mapped to PNs in a distributed manner. Specifically, to decouple the OCSVM objective function, we transform the original problem to a group of decentralized quadratic programming problems by introducing the consensus constraints. The alternating direction method of multipliers is adopted to achieve the solution for the distributed online PN anomaly detection. Next, by utilizing the correlation of measurements between neighbor virtual nodes, another distributed online PL anomaly detection algorithm based on the canonical correlation analysis is proposed. The network only needs to store covariance matrices and mean vectors of current data to calculate the canonical correlation vectors for real-time PL anomaly analysis. The simulation results on both synthetic and real-world network datasets show the effectiveness and robustness of the proposed distributed online anomaly detection algorithms.