...
首页> 外文期刊>IAENG Internaitonal journal of computer science >Country-wide Long-term Event Detection and Classification Mechanisms Using Spatiotemporal BGP Prefix Data
【24h】

Country-wide Long-term Event Detection and Classification Mechanisms Using Spatiotemporal BGP Prefix Data

机译:使用时空BGP前缀数据的全国性长期事件检测和分类机制

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In a network of autonomous systems (ASes), prefix reachability can be affected by events such as link and node failures, router misconfiguration, route flaps and prefix hijack attacks. Furthermore, with the increase in global organizations deploying their data centres and content services in other countries that have good networking infrastructures, studying prefix reachability is of significance. Since detecting these events at the end user level is challenging, by monitoring the spatially distributed routing table features, such as AS path distributions and spatial prefix reachability distributions, the events can be detected at the control plane level. In this work, a measure and a method to detect long term events at a country level AS topology are proposed. To understand the occurrence of control plane level events, temporal pattern analysis over the distributed peer prefix announcements of a country-level AS topology was conducted. Five Asian countries are considered as a representative set to study the occurrence of events. To capture and measure the spatially occurring events in a single temporal pattern, we proposed a counting-based measure using prefixes announced by x % of n spatially distributed peers. Our method to detect events employs mean change point detection technique with normal and CUSUM test statistics over the proposed measure. Other statistical techniques such as regression estimation and K-means clustering are used in our method to quantify the impact and duration of long-term control plane events. The detected events are validated using average path pattern correlation and Fisher scores of different path length features. We also validated the events using the SEA-Me-We4 cable cut event manifestations. The comparison results with other event detection techniques demonstrate the efficacy of the mean change point technique with normal assumption used in our method.
机译:在自治系统(ASes)的网络中,前缀可达性会受到诸如链接和节点故障,路由器配置错误,路由震荡和前缀劫持攻击等事件的影响。此外,随着在具有良好网络基础设施的其他国家/地区中部署数据中心和内容服务的全球组织的增加,研究前缀可及性具有重要意义。由于在最终用户级别检测这些事件具有挑战性,因此通过监视空间分布的路由表功能(例如AS路径分布和空间前缀可达性分布),可以在控制平面级别检测事件。在这项工作中,提出了一种在国家级AS拓扑上检测长期事件的措施和方法。为了了解控制平面级别事件的发生,对国家级AS拓扑的分布式对等前缀通知进行了时间模式分析。五个亚洲国家被认为是研究事件发生的代表。为了捕获和测量单个时间模式中发生的空间事件,我们提出了一种使用n个空间分布的对等点的x%声明的前缀进行基于计数的度量。我们的事件检测方法采用均值变化点检测技术,并在建议的措施上具有正常和CUSUM测试统计信息。在我们的方法中,还使用了其他统计技术,例如回归估计和K-均值聚类来量化长期控制平面事件的影响和持续时间。使用平均路径模式相关性和不同路径长度特征的Fisher分数来验证检测到的事件。我们还使用SEA-Me-We4电缆切割事件表现对事件进行了验证。与其他事件检测技术的比较结果证明了在我们的方法中使用正常假设的均值变化点技术的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号