首页> 外文期刊>Procedia Computer Science >Automated Anomaly Detection in Virtualized Services Using Deep Packet Inspection
【24h】

Automated Anomaly Detection in Virtualized Services Using Deep Packet Inspection

机译:使用深度包检查的虚拟化服务中的自动异常检测

获取原文
           

摘要

Virtualization technologies have proven to be important drivers for the fast and cost-efficient development and deployment of services. While the benefits are tremendous, there are many challenges to be faced when developing or porting services to virtualized infrastructure. Especially critical applications like Virtualized Network Functions must meet high requirements in terms of reliability and resilience. An important tool when meeting such requirements is detecting anomalous system components and recovering the anomaly before it turns into a fault and subsequently into a failure visible to the client. Anomaly detection for virtualized services relies on collecting system metrics that represent the normal operation state of every component and allow the usage of machine learning algorithms to automatically build models representing such state. This paper presents an approach for collecting service-layer metrics while treating services as black-boxes. This allows service providers to implement anomaly detection on the application layer without the need to modify third-party software. Deep Packet Inspection is used to analyse the traffic of virtual machines on the hypervisor layer, producing both generic and protocol-specific communication metrics. An evaluation shows that the resulting metrics represent the normal operation state of an example Virtualized Network Function and are therefore a valuable contribution to automatic anomaly detection in virtualized services.
机译:事实证明,虚拟化技术是快速,经济高效地开发和部署服务的重要驱动力。尽管好处是巨大的,但是在将服务开发或移植到虚拟化基础架构时仍然面临许多挑战。特别重要的应用程序(例如虚拟化网络功能)必须在可靠性和弹性方面满足较高的要求。满足此类要求的重要工具是检测异常的系统组件,并在异常转变成故障然后再转变为客户端可见的故障之前对其进行恢复。虚拟服务的异常检测依赖于收集代表每个组件正常运行状态的系统指标,并允许使用机器学习算法来自动构建代表这种状态的模型。本文提出了一种在将服务视为黑匣子的同时收集服务层指标的方法。这使服务提供商可以在应用程序层上实施异常检测,而无需修改第三方软件。深度数据包检查用于分析虚拟机管理程序层上的虚拟机流量,从而生成通用和特定于协议的通信指标。评估表明,所得度量代表示例虚拟网络功能的正常运行状态,因此对虚拟服务中的自动异常检测做出了宝贵的贡献。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号