TY - JOUR
T1 - Real-time behaviour profiling for network monitoring
AU - Xu, Kuai
AU - Wang, Feng
AU - Bhattacharyya, Supratik
AU - Zhang, Zhi Li
PY - 2010/4
Y1 - 2010/4
N2 - This paper presents the design and implementation of a real-time behaviour profiling system for internet links. The system uses flow-level information, and applies data mining and information-theoretic techniques to automatically discover significant events based on communication patterns. We demonstrate the operational feasibility of the system by implementing it and performing benchmarking of CPU and memory costs using packet traces from backbone links. To improve the robustness of this system against sudden traffic surges, we propose a novel filtering algorithm. The proposed algorithm successfully reduces the CPU and memory cost while maintaining high profiling accuracy. Finally, we devise and evaluate simple yet effective blocking strategies to reduce prevalent exploit traffic, and build a simple event analysis engine to generate ACL rules for filtering unwanted traffic.
AB - This paper presents the design and implementation of a real-time behaviour profiling system for internet links. The system uses flow-level information, and applies data mining and information-theoretic techniques to automatically discover significant events based on communication patterns. We demonstrate the operational feasibility of the system by implementing it and performing benchmarking of CPU and memory costs using packet traces from backbone links. To improve the robustness of this system against sudden traffic surges, we propose a novel filtering algorithm. The proposed algorithm successfully reduces the CPU and memory cost while maintaining high profiling accuracy. Finally, we devise and evaluate simple yet effective blocking strategies to reduce prevalent exploit traffic, and build a simple event analysis engine to generate ACL rules for filtering unwanted traffic.
KW - Behaviour profiling
KW - Profiling-aware filtering algorithms
KW - Real-time traffic monitoring
UR - http://www.scopus.com/inward/record.url?scp=77950964456&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=77950964456&partnerID=8YFLogxK
U2 - 10.1504/IJIPT.2010.032616
DO - 10.1504/IJIPT.2010.032616
M3 - Article
AN - SCOPUS:77950964456
SN - 1743-8209
VL - 5
SP - 65
EP - 80
JO - International Journal of Internet Protocol Technology
JF - International Journal of Internet Protocol Technology
IS - 1-2
ER -