NeTS-NBD-SGER: Map/Reduce for Network Traffic Analysis (MR-Net Sger)
NeTS-NBD-SGER: Map/Reduce for Network Traffic Analysis (MR-Net Sger)
批准号:
0823774
负责人:
John Heidemann
金额:
$10.02万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-04-01 至 2010-03-31
中文摘要
0823774这个项目探索了一类新的并行算法,可以处理非常大的网络数据集。目标是能够分析27亿次ping来绘制互联网地址空间,处理六个月的流量记录来了解长期流量趋势,并搜索一周。的数据包标头的价值,以追溯检测零日受损的机器。这些任务中的每一个都需要高效和经济地处理大小从50 GB到几TB的数据集。数据集大小的这一飞跃是100-1000倍或更多,需要与今天完全不同的处理网络数据的方式。的tcpdump和ethereal。最近的两个发展使这一飞跃成为可能。首先,Google已经证明了map/reduce抽象可以很容易地并行化,并且可以在数百台商用PC的集群上高效、经济地运行。它是他们的网络搜索引擎的基础,并促使至少一个开源实现。Map/Reduce是Google的计算引擎吗?的网络搜索引擎,越来越多地用于其他应用程序。Map/Reduce是处理大型网络数据集的关键。其次,最近的计划,如预测,使大量的网络数据集可用。PREDICT承诺提供来自几个大型ISP的数据包报头跟踪、地址空间扫描、网络流记录、暗地址空间流量和IP语音(VoIP)呼叫记录。在南加州大学,研究人员正在收集数据包报头跟踪和地址空间扫描。PREDICT是获取庞大网络数据集的关键。这项工作是作为SGER提出的,因为它既及时,在这一点上,高度投机。研究人员必须先确定map/reduce可以解决哪些网络问题,然后才能给出可信的完整建议。这个建议是关键,展示了巨大的网络数据集的map/reduce处理的潜在影响,以改变我们对互联网的理解。这项工作的智力价值是开发一个初步的理解,如何使用map/reduce风格处理网络数据集。哪些算法适用?哪些问题并行性好或差?需要什么样的计算集群?更一般地说,网络研究人员如何科普描述十亿用户互联网所需的千兆字节到兆字节的数据集?这项工作的更广泛的优点是,它将导致互联网面临的基本和实际问题的答案。考虑到这些数据集,问题包括:互联网是什么样子的?互联网地址空间的消耗率是多少?有多少互联网用户使用动态地址连接?如何有效应对入侵?新技术能否检测到低速率的拒绝服务攻击、受感染服务器中的垃圾邮件生成?可以追溯和检测僵尸网络控制网络?比这些具体问题更重要的是一个更广泛的问题,即如何理解十亿节点互联网的属性以及每天在其上流动的PB流量。
英文摘要
0823774This project explores a new class of parallel algorithms that process very large network datasets. The goal is to be able to analyze 2.7 billion pings to map the Internet address space, process six months of flow records to understand long-term traffic trends, and search a week?s worth of packet headers to retroactively detect zero-day compromised machines. Each of these tasks requires efficient and economical processing of datasets in sizes from 50GB to several terabytes. This leap in dataset sizes by a factor of 100-1000-fold or more requires fundamentally different ways of handling network data than today?s tcpdump and ethereal on a workstation. Two recent developments make this leap possible. First, Google has demonstrated that the map/reduce abstraction be easily parallelized and run efficiently and cost-effectively over clusters of hundreds of commodity PCs. It is the basis of their web search engine and has prompted at least one open source implementation. Map/reduce is the computation engine of Google?s web search engine, increasingly being used in other applications. Map/reduce is the key to processing huge network datasets. Second, recent programs such as PREDICT make massive network datasets available. PREDICT promises to make available packet header traces, address space scans, netflow records, dark address space traffic, and voice over IP (VoIP) call records from several large ISPs. At USC researchers are collecting packet header traces and address space scans. PREDICT is the key to obtaining huge network datasets. This work is proposes as a SGER because it is both timely and, at this point, highly speculative. The researchers must characterize what network problems can be solved by map/reduce before a full proposal will be credible. This proposal is the key to demonstrating the potential impact of for map/reduce processing of huge network datasets to change our understanding of the Internet.The intellectual merit of this work is to develop a preliminary understanding of how to use map/reduce style processing for network datasets. What algorithms are applicable? What problems parallelize well or poorly? What kind of compute clusters are needed? And more generally, how can networking researchers cope with gigabyte-to-terabyte datasets that are needed to describe a billion-user Internet?The broader merit of this work is that it will lead to answers of both fundamental and practical questions facing the Internet. Considering these datasets, questions include: What does the Internet look like? At what rate is the Internet address space being consumed? How many Internet users connect with dynamic addresses? How can one respond to intrusions effectively? Can new techniques detect low-rate denial-of-service attacks, spam generation in compromised servers? Can one traceback and detect botnets control networks? More important than these specific questions is the broader question of how can one understand properties in a billion-node Internet and the petabyte-per day of traffic that flows over it.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: IMR:MM-1B: Privacy in Internet Measurements Applied To WAN and Telematics
-
批准号:2319409
-
项目类别:Continuing Grant
-
资助金额:$26.91万
-
财政年份:2023
-
负责人:John Heidemann
-
依托单位:
IMR: RI-P: Safe And Flexible Experimental Dataset Access and Sharing-Planning (SAFED-ASP)
-
批准号:2224467
-
项目类别:Standard Grant
-
资助金额:$9.91万
-
财政年份:2022
-
负责人:John Heidemann
-
依托单位:
Collaborative Research: CNS Core: Medium: A Traffic Map for the Internet
-
批准号:2212480
-
项目类别:Continuing Grant
-
资助金额:$39.8万
-
财政年份:2022
-
负责人:John Heidemann
-
依托单位:
RAPID: Measuring the Internet during Novel Coronavirus to Evaluate Quarantine (RAPID-MINSEQ)
-
批准号:2028279
-
项目类别:Standard Grant
-
资助金额:$9.9万
-
财政年份:2020
-
负责人:John Heidemann
-
依托单位:
CNS Core: Small: Event Identification in Evaluation of Internet Outages
-
批准号:2007106
-
项目类别:Standard Grant
-
资助金额:$48.33万
-
财政年份:2020
-
负责人:John Heidemann
-
依托单位:
CCRI: Medium: DNS, Identity, and Internet Naming for Experimentation and Research (DIINER)
-
批准号:1925737
-
项目类别:Continuing Grant
-
资助金额:$145.84万
-
财政年份:2019
-
负责人:John Heidemann
-
依托单位:
RAPID: Interactive Internet Outages Visualization to Assess Disaster Recovery
-
批准号:1806785
-
项目类别:Standard Grant
-
资助金额:$19.89万
-
财政年份:2018
-
负责人:John Heidemann
-
依托单位:
CICI: RSARC: DDoS Defense In Depth for DNS
-
批准号:1739034
-
项目类别:Standard Grant
-
资助金额:$99.72万
-
财政年份:2017
-
负责人:John Heidemann
-
依托单位:
CI-P: Planning for Identity and Naming Experimentation Shared Testbed
-
批准号:1513213
-
项目类别:Standard Grant
-
资助金额:$10.0万
-
财政年份:2015
-
负责人:John Heidemann
-
依托单位:
MRI: Development of an Always-Available Testbed for Underwater Networking Research
-
批准号:0821750
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2008
-
负责人:John Heidemann
-
依托单位:
CRI: CRD: Collaborative Research: Open Research Testbed for Underwater Ad Hoc and Sensor Networks
-
批准号:0708946
-
项目类别:Continuing Grant
-
资助金额:$15.0万
-
财政年份:2007
-
负责人:John Heidemann
-
依托单位:
NeTS-FIND: Sensor-Internet Sharing and Search
-
批准号:0626702
-
项目类别:Standard Grant
-
资助金额:$0.0万
-
财政年份:2006
-
负责人:John Heidemann
-
依托单位:
NeTs-NBD: Maltraffic Analysis and Detection in Challenging and Aggregate Traffic (MADCAT)
-
批准号:0626696
-
项目类别:Standard Grant
-
资助金额:$89.65万
-
财政年份:2006
-
负责人:John Heidemann
-
依托单位:
NeTS-NOSS: Sensor Networks for Undersea Seismic Experimentation (SNUSE)
-
批准号:0435517
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2004
-
负责人:John Heidemann
-
依托单位:
ITR: MAC Protocols Specific for Sensor Networks (MACSS)
-
批准号:0220026
-
项目类别:Continuing Grant
-
资助金额:$30.0万
-
财政年份:2002
-
负责人:John Heidemann
-
依托单位:
Collaborative Simulation for Education and Research
-
批准号:9986208
-
项目类别:Continuing Grant
-
资助金额:$150.51万
-
财政年份:2000
-
负责人:John Heidemann
-
依托单位:
国内基金
海外基金
登录
查看更多内容
效应因子NBD在菰黑粉菌侵染中的作用机制
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:夏文强
-
依托单位:
ABCC2基因NBD区突变影响MRP2亚细胞定位及降解在Dubin-Johnson综合征中的致病作用及机制
-
批准号:82000543
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:武丽娜
-
依托单位:
基于三维打印Sr-CaS/NBD多肽缓释微球支架材料修复感染性骨缺损的实验研究
-
批准号:81601911
-
项目类别:青年科学基金项目
-
资助金额:18.0万元
-
批准年份:2016
-
负责人:李雪
-
依托单位:
炎症刺激下NBD多肽对成骨细胞分化作用的机制研究
-
批准号:81272052
-
项目类别:面上项目
-
资助金额:70.0万元
-
批准年份:2012
-
负责人:余斌
-
依托单位:
基于量子点/NBD荧光比率的高灵敏、高通量功能寡糖筛选和构效关系评估体系构建及其应用
-
批准号:31201384
-
项目类别:青年科学基金项目
-
资助金额:25.0万元
-
批准年份:2012
-
负责人:张洪涛
-
依托单位:
TAT-NBD及ERK通路防治胆红素神经毒性的研究
-
批准号:81200459
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2012
-
负责人:华子瑜
-
依托单位: