首页> 外文会议>International Conference on Network Protocols >Anomalous Model-Driven-Telemetry Network-Stream BGP Detection
【24h】

Anomalous Model-Driven-Telemetry Network-Stream BGP Detection

机译:异常模型驱动遥测网络流BGP检测

获取原文

摘要

There is a growing demand for real-time analysis of network data streams. In recent years, Model Driven Telemetry (MDT) has been developed – in place of conventional methods such as Simple Network Management Protocol (SNMP), Syslog and CLI commands – to provide a fine-grain holistic view of a network at the control, data and management planes. High-frequency MDT data streams generated from network devices enable new ways of designing Network Operation and Management (OAM) solutions, laying the foundation for future "self-driving" networks.In this paper we study anomaly detection using MDT data streams in a data center environment. In many commercial data centers, BGP is re-purposed for (policy-driven, path-based) intra-routing (as opposed to inter-domain routing that it was originally designed for) to take advantage of rich path diversity. Several vendors have developed MDT data models using YANG that allow routers/switches to express and stream various BGP features for (centralized) network OAM operations. We develop a systematic MDT data processing and feature selection framework that is portable to multiple MDT vendors. Furthermore, we advance NetCorDenstream that builds and improves upon OutlierDenStream proposed in [10] for real-time detection of streamed anomalous MDT data. We show that NetCorDenstream achieves a 59% reduction in alarms raised when compared with OutlierDenStream, thereby reducing the (attention) burden placed on network operators. In particular, it increases alarm detection precision significantly while decreasing false alarms at the expense of a slightly delayed response time.
机译:对网络数据流的实时分析的需求不断增长。近年来,已经开发了模型驱动遥测(MDT)–代替了诸如简单网络管理协议(SNMP),Syslog和CLI命令之类的传统方法–以提供控制,数据和网络的细粒度整体视图。和管理飞机。从网络设备生成的高频MDT数据流为设计网络运营和管理(OAM)解决方案提供了新方法,为将来的“自动驾驶”网络奠定了基础。在本文中,我们研究了使用数据中的MDT数据流进行异常检测。中心环境。在许多商业数据中心中,BGP被重新用于(策略驱动的,基于路径的)内部路由(与最初为其设计的域间路由相反),以利用丰富的路径多样性。多家供应商已经开发了使用YANG的MDT数据模型,该模型允许路由器/交换机为(集中式)网络OAM操作表达和流式传输各种BGP功能。我们开发了系统的MDT数据处理和功能选择框架,可移植到多个MDT供应商。此外,我们改进了NetCorDenstream,它构建和改进了[10]中提出的OutlierDenStream,用于实时检测流式异常MDT数据。我们显示,与OutlierDenStream相比,NetCorDenstream发出的警报减少了59%,从而减轻了网络运营商的(注意力)负担。特别是,它显着提高了警报检测精度,同时减少了误警报,但响应时间略有延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号