DocumentCode
2017587
Title
NSDMiner: Automated discovery of Network Service Dependencies
Author
Natarajan, Arun ; Ning, Peng ; Liu, Yao ; Jajodia, Sushil ; Hutchinson, Steve E.
Author_Institution
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
fYear
2012
fDate
25-30 March 2012
Firstpage
2507
Lastpage
2515
Abstract
Enterprise networks today host a wide variety of network services, which often depend on each other to provide and support network-based services and applications. Understanding such dependencies is essential for maintaining the well-being of an enterprise network and its applications, particularly in the presence of network attacks and failures. In a typical enterprise network, which is complex and dynamic in configuration, it is non-trivial to identify all these services and their dependencies. Several techniques have been developed to learn such dependencies automatically. However, they are either too complex to fine tune or cluttered with false positives and/or false negatives. In this paper, we propose a suite of novel techniques and develop a new tool named NSDMiner (which stands for Mining for Network Service Dependencies) to automatically discover the dependencies between network services from passively collected network traffic. NSDMiner is non-intrusive; it does not require any modification of existing software, or injection of network packets. More importantly, NSDMiner achieves higher accuracy than previous network-based approaches. Our experimental evaluation, which uses network traffic collected from our campus network, shows that NSDMiner outperforms the two best existing solutions significantly.
Keywords
Internet; business data processing; data mining; telecommunication traffic; NSDMiner; automated discovery; campus network; enterprise network; mining for network service dependencies; network attack; network failure; passively collected network traffic; Databases; Electronic mail; Monitoring; Protocols; Web servers;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM, 2012 Proceedings IEEE
Conference_Location
Orlando, FL
ISSN
0743-166X
Print_ISBN
978-1-4673-0773-4
Type
conf
DOI
10.1109/INFCOM.2012.6195642
Filename
6195642
Link To Document