• DocumentCode
    775521
  • Title

    Detecting Network-Wide and Router-Specific Misconfigurations Through Data Mining

  • Author

    Le, Franck ; Lee, Sihyung ; Wong, Tina ; Kim, Hyong S. ; Newcomb, Darrell

  • Author_Institution
    Carnegie Mellon Univ., Pittsburgh, PA
  • Volume
    17
  • Issue
    1
  • fYear
    2009
  • Firstpage
    66
  • Lastpage
    79
  • Abstract
    Recent studies have shown that router misconfigurations are common and can have dramatic consequences to the operations of a network. Misconfigurations can compromise the security of an entire network or even cause global disruptions to Internet connectivity. Several solutions have been proposed. They can detect a number of problems in real configuration files. However, these solutions share a common limitation: they are based on rules which need to be known beforehand. Violations of these rules are deemed misconfigurations. As policies typically differ among networks, these approaches are limited in the scope of mistakes they can detect. In this paper, we address the problem of router misconfigurations using data mining. We apply association rules mining to the configuration files of routers across an administrative domain to discover local, network-specific policies. Deviations from these local policies are potential misconfigurations. We have evaluated our scheme on configuration files from a large state-wide network provider, a large university campus and a high-performance research network. In this evaluation, we focused on three aspects of the configurations: user accounts, interfaces and BGP sessions. User accounts specify the users that can access the router and define the authorized commands. Interfaces are the ports used by routers to connect to different networks. Each interface may support a number of services and run various routing protocols. BGP sessions are the connections with neighboring autonomous systems (AS). BGP sessions implement the routing policies which select the routes that are filtered and the ones that are advertised to the BGP neighbors. We included the routing policies in our study. The results are promising. We discovered a number of errors that were confirmed and corrected by the network administrators. These errors would have been difficult to detect with current predefined rule-based approaches.
  • Keywords
    Internet; computer networks; configuration management; data mining; telecommunication network management; telecommunication network routing; BGP sessions; Internet connectivity; association rules mining; autonomous systems; data mining; interface session; networkwide misconfiguration; router misconfigurations; router specific misconfiguration; user accounts; Association rules mining; error detection; network management; static analysis;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2008.925631
  • Filename
    4553724