• DocumentCode
    2017587
  • Title

    NSDMiner: Automated discovery of Network Service Dependencies

  • Author

    Natarajan, Arun ; Ning, Peng ; Liu, Yao ; Jajodia, Sushil ; Hutchinson, Steve E.

  • Author_Institution
    Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
  • fYear
    2012
  • fDate
    25-30 March 2012
  • Firstpage
    2507
  • Lastpage
    2515
  • Abstract
    Enterprise networks today host a wide variety of network services, which often depend on each other to provide and support network-based services and applications. Understanding such dependencies is essential for maintaining the well-being of an enterprise network and its applications, particularly in the presence of network attacks and failures. In a typical enterprise network, which is complex and dynamic in configuration, it is non-trivial to identify all these services and their dependencies. Several techniques have been developed to learn such dependencies automatically. However, they are either too complex to fine tune or cluttered with false positives and/or false negatives. In this paper, we propose a suite of novel techniques and develop a new tool named NSDMiner (which stands for Mining for Network Service Dependencies) to automatically discover the dependencies between network services from passively collected network traffic. NSDMiner is non-intrusive; it does not require any modification of existing software, or injection of network packets. More importantly, NSDMiner achieves higher accuracy than previous network-based approaches. Our experimental evaluation, which uses network traffic collected from our campus network, shows that NSDMiner outperforms the two best existing solutions significantly.
  • Keywords
    Internet; business data processing; data mining; telecommunication traffic; NSDMiner; automated discovery; campus network; enterprise network; mining for network service dependencies; network attack; network failure; passively collected network traffic; Databases; Electronic mail; Monitoring; Protocols; Web servers;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM, 2012 Proceedings IEEE
  • Conference_Location
    Orlando, FL
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4673-0773-4
  • Type

    conf

  • DOI
    10.1109/INFCOM.2012.6195642
  • Filename
    6195642