欢迎来到天天文库
浏览记录
ID:41331212
大小:365.81 KB
页数:23页
时间:2019-08-22
《OnlineIdentificationofHierarchicalHeavyHitters分层重量级的在线辨识》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、OnlineIdentificationofHierarchicalHeavyHittersYinZhangyzhang@research.att.comJointworkwithSumeetSinghSubhabrataSenNickDuffieldCarstenLundInternetMeasurementConference2004MotivationTrafficanomaliesarecommonDDoSattacks,Flashcrowds,worms,failuresTrafficanomaliesarecomplicatedMulti-dimensiona
2、lmayinvolvemultipleheaderfieldsE.g.srcIP1.2.3.4ANDport1214(KaZaA)Lookingatindividualfieldsseparatelyisnotenough!HierarchicalEvidentonlyatspecificgranularitiesE.g.1.2.3.4/32,1.2.3.0/24,1.2.0.0/16,1.0.0.0/8Lookingatfixedaggregationlevelsisnotenough!Wanttoidentifyanomaloustrafficaggregates
3、automatically,accurately,innearrealtimeOfflineversionconsideredbyEstanetal.[SIGCOMM03]2ChallengesImmensedatavolume(esp.duringattacks)ProhibitivetoinspectalltrafficindetailMulti-dimensional,hierarchicaltrafficanomaliesProhibitivetomonitorallpossiblecombinationsofdifferentaggregationlevelso
4、nallheaderfieldsSampling(packetlevelorflowlevel)MaywashoutsomedetailsFalsealarmsToomanyalarms=info“snow”simplygetignoredRootcauseanalysisWhatdoanomaliesreallymean?3ApproachPrefilteringextractsmulti-dimensionalhierarchicaltrafficclustersFast,scalable,accurateAllowsdynamicdrilldownRobusthe
5、avyhitter&changedetectionDealswithsamplingerrors,missingvaluesCharacterization(ongoing)ReducefalsealarmsbycorrelatingmultiplemetricsCanpipetoexternalsystemsPrefiltering(extractclusters)Identification(robustHH&CD)CharacterizationInputOutput4PrefilteringInput6、rt,proto>Bytes(wecanalsouseothermetrics)OutputAlltrafficclusterswithvolumeabove(epsilon*total_volume)(clusterID,estimatedvolume)Trafficclusters:definedusingcombinationsofIPprefixes,portranges,andprotocolGoalsSinglePassEfficient(lowoverhead)Dynamicdrilldowncapability5DynamicDrilldownvia1-7、DTrieAtmost1updateperflowSplitlevelwhenaddingnewbytescausesbucket>=TsplitInvariant:traffictrappedatanyinteriornode
6、rt,proto>Bytes(wecanalsouseothermetrics)OutputAlltrafficclusterswithvolumeabove(epsilon*total_volume)(clusterID,estimatedvolume)Trafficclusters:definedusingcombinationsofIPprefixes,portranges,andprotocolGoalsSinglePassEfficient(lowoverhead)Dynamicdrilldowncapability5DynamicDrilldownvia1-
7、DTrieAtmost1updateperflowSplitlevelwhenaddingnewbytescausesbucket>=TsplitInvariant:traffictrappedatanyinteriornode
此文档下载收益归作者所有