Abstract

Detecting and understanding anomalies in IP networks is an open and ill-defined problem. Toward this end, we have recently proposed the subspace method for anomaly diagnosis. In this paper we present the first large-scale exploration of the power of the subspace method when applied to flow traffic. An important aspect of this approach is that it fuses information from flow measurements taken throughout a network. We apply the subspace method to three different types of sampled flow traffic in a large academic network: multivariate timeseries of byte counts, packet counts, and IP-flow counts. We show that each traffic type brings into focus a different set of anomalies via the subspace method. We illustrate and classify the set of anomalies detected. We find that almost all of the anomalies detected represent events of interest to network operators. Furthermore, the anomalies span a remarkably wide spectrum of event types, including denial of service attacks (single-source and distributed), flash crowds, port scanning, downstream traffic engineering, high-rate flows, worm propagation, and network outage.


Original document

The different versions of the original document can be found in:

http://www.cs.unc.edu/~jeffay/courses/nidsS05/signal-proc/anomalychar-imc04.pdf,
http://conferences.sigcomm.org/imc/2004/papers/p201-lakhina.pdf,
http://www.cs.princeton.edu/courses/archive/spr05/cos598E/bib/anomalychar-imc04.pdf,
http://www.cs.bu.edu/techreports/pdf/2004-020-traffic-flow-anomalies.pdf,
https://dl.acm.org/citation.cfm?id=1028813,
http://core.ac.uk/display/24387073,
https://doi.acm.org/10.1145/1028788.1028813,
https://open.bu.edu/handle/2144/1546,
http://portal.acm.org/citation.cfm?doid=1028788.1028813,
https://conferences2.sigcomm.org/imc/2004/papers/p201-lakhina.pdf,
https://dblp.uni-trier.de/db/conf/imc/imc2004.html#LakhinaCD04,
https://doi.org/10.1145/1028788.1028813,
https://open.bu.edu/bitstream/2144/1546/1/2004-020-traffic-flow-anomalies.pdf,
https://academic.microsoft.com/#/detail/2144936818
http://dx.doi.org/10.1145/1028788.1028813
Back to Top

Document information

Published on 01/01/2004

Volume 2004, 2004
DOI: 10.1145/1028788.1028813
Licence: CC BY-NC-SA license

Document Score

0

Views 1
Recommendations 0

Share this document

Keywords

claim authorship

Are you one of the authors of this document?