TY - GEN
T1 - A real-time network traffic profiling system
AU - Xu, Kuai
AU - Wang, Feng
AU - Bhattacharyya, Supratik
AU - Zhang, Zhi-Li
N1 - Copyright:
Copyright 2011 Elsevier B.V., All rights reserved.
PY - 2007
Y1 - 2007
N2 - This paper presents the design and implementation of a real-time behavior profiling system for high-speed Internet links. The profiling system uses flow-level information from continuous packet or flow monitoring systems, and uses data mining and information-theoretic techniques to automatically discover significant events based on the communication patterns of end-hosts. We demonstrate the operational feasibility of the system by implementing it and performing extensive benchmarking of CPU and memory costs using a variety of packet traces from OC-48 links in an Internet backbone network. To improve the robustness of this system against sudden traffic surges such as those caused by denial of service attacks or worm outbreaks, we propose a simple yet effective filtering algorithm. The proposed algorithm successfully reduces the CPU and memory cost while maintaining high profiling accuracy.
AB - This paper presents the design and implementation of a real-time behavior profiling system for high-speed Internet links. The profiling system uses flow-level information from continuous packet or flow monitoring systems, and uses data mining and information-theoretic techniques to automatically discover significant events based on the communication patterns of end-hosts. We demonstrate the operational feasibility of the system by implementing it and performing extensive benchmarking of CPU and memory costs using a variety of packet traces from OC-48 links in an Internet backbone network. To improve the robustness of this system against sudden traffic surges such as those caused by denial of service attacks or worm outbreaks, we propose a simple yet effective filtering algorithm. The proposed algorithm successfully reduces the CPU and memory cost while maintaining high profiling accuracy.
UR - http://www.scopus.com/inward/record.url?scp=36048955492&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=36048955492&partnerID=8YFLogxK
U2 - 10.1109/DSN.2007.10
DO - 10.1109/DSN.2007.10
M3 - Conference contribution
AN - SCOPUS:36048955492
SN - 0769528554
SN - 9780769528557
T3 - Proceedings of the International Conference on Dependable Systems and Networks
SP - 595
EP - 604
BT - Proceedings - 37th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2007
T2 - 37th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2007
Y2 - 25 June 2007 through 28 June 2007
ER -