DocumentCode :
2137767
Title :
A scalable high performance network monitoring agent for CERNET
Author :
Hui, ZHANG ; Xing, LI ; Zimu, Li
Author_Institution :
CERNET Network Res. Center, Tsinghua Univ., Beijing, China
fYear :
2003
fDate :
27-29 Aug. 2003
Firstpage :
151
Lastpage :
156
Abstract :
In a cost-effective way, collecting and analyzing data from such a nationwide operational network as China Education and Research Network (CERNET) is an increasingly challenging task. We present experience gained in designing and implementing a passive monitoring agent applicable to CERNET, which helps to cooperate not only with network intrusion detection system (IDS), network management system (NMS) for detecting and identifying signs of malicious activities, nonmalicious failures and other exceptional events in real-time, but provides anomaly information to accounting and billing system (ABS) so as to make it healthy. This agent is characterized by a high performance data collecting facility and a methodology of real-time data correlation and analysis. A customized agent can be deployed on a particular link of CERNET for monitoring network dynamically. We discuss how to conflate, correlate, associate and refine measurement data to discriminate anomalies such as DoS from normal traffic, and how to respond to the anomalies for the purpose of operational network´s health. It concludes with experiences learned from the development and deployment of the agent and ongoing research work.
Keywords :
IP networks; computer network management; data mining; monitoring; security of data; software agents; telecommunication security; CERNET; China Education and Research Network; data mining; intrusion detection system; network management system; packet classification; passive monitoring agent; scalable high performance network monitoring agent; traffic collection; Bandwidth; Computer science education; Computerized monitoring; Condition monitoring; Data analysis; Event detection; Intrusion detection; Peer to peer computing; Spine; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Computing, Applications and Technologies, 2003. PDCAT'2003. Proceedings of the Fourth International Conference on
Print_ISBN :
0-7803-7840-7
Type :
conf
DOI :
10.1109/PDCAT.2003.1236277
Filename :
1236277
Link To Document :
بازگشت