DocumentCode :
2306532
Title :
Real-time measurement of flows classified according to their application
Author :
Ohta, Satoru ; Zhu, Shan
Author_Institution :
Dept. of Inf. Syst. Eng., Toyama Prefectural Univ., Imizu, Japan
fYear :
2011
fDate :
21-23 Sept. 2011
Firstpage :
1
Lastpage :
8
Abstract :
In the management of Internet Protocol networks, the number of flows is an important performance metric because it has useful applications in areas such as port scan detection, denial-of-service detection, and traffic analysis. Real-time counting of flows is particularly important because network operators can take immediate actions against detected network anomalies or performance degradation. This paper presents a method that enables real-time counting of flows classified by application. More useful information for network management can be obtained by counting classified flows. For example, the proposed method is helpful in determining the type of attacks or victim services for attack detection. The algorithm for counting classified flows is developed using the timestamp vector algorithm. This paper first explores a naïve method that has as many timestamp vector mechanisms as the application classes. However, this method is disadvantageous because it consumes very large memory space. To avoid this problem, a new method that considerably decreases memory consumption is proposed. In addition, the paper also investigates a method for improving measurement accuracy. The effectiveness of the proposed method is evaluated for real-world network data.
Keywords :
Internet; computer network performance evaluation; computer network security; protocols; Internet protocol networks; denial-of-service detection; naive method; performance metric; port scan detection; real time flows measurement; timestamp vector algorithm; traffic analysis; victim services; Classification algorithms; Memory management; Protocols; Real time systems; Support vector machine classification; TV; Vectors; application; flows; internet protocol; measurement; performance; traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (APNOMS), 2011 13th Asia-Pacific
Conference_Location :
Taipei
Print_ISBN :
978-1-4577-1668-3
Type :
conf
DOI :
10.1109/APNOMS.2011.6077017
Filename :
6077017
Link To Document :
بازگشت