Abstract
Anomaly detection remains a poorly understood area where visual inspection and manual analysis play a significant role in the effectiveness of the detection technique. We observe traffic anomalies in two adjacent networks, namely GEANT and Abilene, in order to determine what parameters impact the detectability and the characteristics of anomalies. We correlate three weeks of traffic and routing data from both networks and apply Kalman filtering to detect anomalies that transit between the two networks. We show that differences in the monitoring infrastructure, network engineering practices, and anomaly-detection parameters have a large impact on which anomaly detectability. Through a case study of three specific anomalies, we illustrate the influence of the traffic mix, IP address anonymization, detection methodology, and packet sampling on the detectability of traffic anomalies.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
References
Lakhina, A., Crovella, M., Diot, C.: Diagnosing network-wide traffic anomalies. In: ACM Sigcomm, ACM Press, New York (2004)
Soule, A., Salamatian, K., Taft, N., Nucci, A.: Traffic matrix tracking using kalman filters. In: ACM LSNI Workshop, ACM Press, New York (2005)
Soule, A., Salamatian, K., Taft, N.: Combining filtering and statistical methods for anomaly detection. In: ACM IMC, October, ACM Press, New York (2005)
Zhang, Y., Ge, Z., Greenberg, A., Roughan, M.: Network anomography. In: ACM IMC, October, ACM Press, New York (2005)
Teixeira, R., Duffield, N.G., Rexford, J., Roughan, M.: Traffic matrix reloaded: Impact of routing changes. In: Dovrolis, C. (ed.) PAM 2005. LNCS, vol. 3431, Springer, Heidelberg (2005)
Brauckhoff, D., Tellenbach, B., Wagner, A., Lakhina, A., May, M.: The effect of packet sampling on anomaly detection. In: ACM IMC, October, ACM Press, New York (2006)
Barakat, C., Iannaccone, G., Diot, C.: Ranking flows from sampled traffic. In: ACM CoNEXT, December, ACM Press, New York (2005)
Author information
Authors and Affiliations
Editor information
Rights and permissions
Copyright information
© 2007 Springer Berlin Heidelberg
About this paper
Cite this paper
Soule, A., Ringberg, H., Silveira, F., Rexford, J., Diot, C. (2007). Detectability of Traffic Anomalies in Two Adjacent Networks. In: Uhlig, S., Papagiannaki, K., Bonaventure, O. (eds) Passive and Active Network Measurement. PAM 2007. Lecture Notes in Computer Science, vol 4427. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-71617-4_3
Download citation
DOI: https://doi.org/10.1007/978-3-540-71617-4_3
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-71616-7
Online ISBN: 978-3-540-71617-4
eBook Packages: Computer ScienceComputer Science (R0)