DocumentCode
2288086
Title
Finding Heavy Hitters by Packet Count Flow Sampling
Author
Zhu, Zhuyang ; Zhang, Hai ; Guo, Wenming
Author_Institution
Network center, Southern Med. Univ., Guangzhou
fYear
2008
fDate
20-22 Dec. 2008
Firstpage
834
Lastpage
838
Abstract
In many applications, ranging from network congestion monitoring to data mining, it is often desirable to identify from a large data set whose frequency is above a given threshold. This can help us find out the heaviest users, most popular web sites and so on.Our work focus on packet count heavy hitters finding problem , especially suite for Some attacks such as SYN flood and port scans. These kind of anomaly will not occupy much bandwidth, but still can affect the Internet seriously. A major difficulty with detecting heavy hitters on a high-speed monitoring point is that the traffic volume can contain millions of flows. So we present a threshold sampling technique. It can select large ones prior to small ones.Meanwhile, it can control the resources consumed by adjusting the threshold. The main procedures of this method is the source IP address base packet count aggregating and sorting. The experimental results show that heavy hitters from the sample approximate that from the original dataset, proofing that our method are effective.
Keywords
Internet; security of data; Internet; data mining; heavy hitters; high-speed monitoring; network congestion monitoring; packet count aggregating; packet count flow sampling; packet count sorting; source IP address; threshold sampling technique; Bandwidth; Computer networks; Counting circuits; Floods; Frequency; Internet; Monitoring; Sampling methods; Sorting; Telecommunication traffic; heavy hitters; packet count; sampling;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Electrical Engineering, 2008. ICCEE 2008. International Conference on
Conference_Location
Phuket
Print_ISBN
978-0-7695-3504-3
Type
conf
DOI
10.1109/ICCEE.2008.90
Filename
4741101
Link To Document