...
首页> 外文期刊>IEEE Journal on Selected Areas in Communications >AMON: An Open Source Architecture for Online Monitoring, Statistical Analysis, and Forensics of Multi-Gigabit Streams
【24h】

AMON: An Open Source Architecture for Online Monitoring, Statistical Analysis, and Forensics of Multi-Gigabit Streams

机译:AMON:一种用于多千兆位流的在线监视,统计分析和取证的开源体系结构

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The Internet, as a global system of interconnected networks, carries an extensive array of information resources and services. Key requirements include good quality-of-service and protection of the infrastructure from nefarious activity [e.g., distributed denial of service (DDoS) attacks]. Network monitoring is essential to network engineering, capacity planning, and prevention/mitigation of threats. We develop an open-source architecture, All-packet MONitor (AMON), for online monitoring and analysis of multi-gigabit network streams. It leverages the high-performance packet monitor PF_RING and is readily deployable on commodity hardware. AMON examines all packets, partitions traffic into sub-streams by using rapid hashing and computes certain real-time data products. The resulting data structures provide views of the intensity and connectivity structure of network traffic at the time-scale of routing. The proposed integrated framework includes modules for the identification of heavy-hitters as well as for visualization and statistical detection at the time-of-onset of high-impact events such as DDoS. This allows operators to quickly visualize and diagnose attacks, and limit offline and time-consuming post-mortem analysis. We demonstrate our system in the context of real-world attack incidents, and validate it against state-of-the-art alternatives. AMON has been deployed and is currently processing multi-gigabit live Internet traffic at Merit Network. It is extensible and allows the addition of further statistical and filtering modules for real-time forensics.
机译:互联网作为互连网络的全球系统,承载着广泛的信息资源和服务。关键要求包括良好的服务质量,以及保护基础架构免受恶意活动(例如,分布式拒绝服务(DDoS)攻击)。网络监视对于网络工程,容量规划以及威胁的预防/缓解至关重要。我们开发了一种开放源代码体系结构全包监视器(AMON),用于在线监视和分析多千兆位网络流。它利用了高性能的数据包监控器PF_RING,可轻松部署在商用硬件上。 AMON检查所有数据包,通过使用快速哈希将流量划分为子流,并计算某些实时数据产品。生成的数据结构在路由的时间尺度上提供了网络流量的强度和连通性结构的视图。提议的集成框架包括用于识别重击者的模块,以及用于在高影响力事件(例如DDoS)发作时进行可视化和统计检测的模块。这使操作员可以快速可视化和诊断攻击,并限制离线和费时的事后分析。我们在真实世界的攻击事件中演示了我们的系统,并针对最新技术进行了验证。 AMON已被部署,目前正在Merit Network处处理千兆级实时Internet流量。它是可扩展的,并允许添加更多的统计和过滤模块以进行实时取证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号