DocumentCode :
558668
Title :
NEPnet: A scalable monitoring system for anomaly detection of network service
Author :
Cheng, Sujun ; Cheng, Zhendong ; Luan, Zhongzhi ; Qian, Depei
Author_Institution :
Beijing Key Lab. of Network Technol., Beihang Univ., Beijing, China
fYear :
2011
fDate :
24-28 Oct. 2011
Firstpage :
1
Lastpage :
5
Abstract :
Anomaly detection is very important for modern network service. Yet it is still a big challenge to conduct effective anomaly detection due to the high rate of service data and the complex correlations among them. Owing to the powerful query language and performance potential, complex event processing (CEP) is very suitable for this situation. In this paper, we present NEPnet, a high-performance and scalable monitoring system, which can process events for anomaly detection of network service in real time. NEPnet is based on CEP and provides a SQL-like language supporting various event correlations. On accepting pre-defined queries as input, NEPnet builds a tree-based monitoring net for detailed anomaly detection. Considering the anomaly features of network service, the monitoring net utilizes limit trigger, predicate index and route table for different types of processing nodes in it. Our preliminary experiment results show that NEPnet can effectively detect anomaly of network service, with a high-speed of 100,000 events per second and 3~6 times faster than Esper, a general CEP engine.
Keywords :
SQL; computer network security; telecommunication network routing; telecommunication network topology; NEPnet; SQL-like language; anomaly detection; complex event processing; limit trigger; monitoring system; network service; performance potential; predicate index; query language; route table; service data; tree-based monitoring net; Correlation; Engines; Indexes; Intrusion detection; Monitoring; Registers; Throughput; anomaly detection; complex event processing; monitoring net; network service;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and Service Management (CNSM), 2011 7th International Conference on
Conference_Location :
Paris
Print_ISBN :
978-1-4577-1588-4
Electronic_ISBN :
978-3-901882-44-9
Type :
conf
Filename :
6103958
Link To Document :
بازگشت