2004
DOI: 10.1145/1030194.1015492
|View full text |Cite
|
Sign up to set email alerts
|

Diagnosing network-wide traffic anomalies

Abstract: Anomalies are unusual and significant changes in a network's traffic levels, which can often involve multiple links. Diagnosing anomalies is critical for both network operators and end users. It is a difficult problem because one must extract and interpret anomalous patterns from large amounts of high-dimensional, noisy data. In this paper we propose a general method to diagnose anomalies. This method is based on a separation of the high-dimensional space occupied by a set of network traffic measurements into … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

1
191
0

Year Published

2009
2009
2020
2020

Publication Types

Select...
8

Relationship

0
8

Authors

Journals

citations
Cited by 395 publications
(232 citation statements)
references
References 28 publications
1
191
0
Order By: Relevance
“…Note that several papers in the networking literature [14,25,26] have relied on a space-time analysis of network traffic, similarly to this paper. Those studies are similar to our work in that they use PCA or Kalman filtering in order to identify abnormal patterns in large traffic datasets.…”
Section: Traffic On the As Topologymentioning
confidence: 99%
See 2 more Smart Citations
“…Note that several papers in the networking literature [14,25,26] have relied on a space-time analysis of network traffic, similarly to this paper. Those studies are similar to our work in that they use PCA or Kalman filtering in order to identify abnormal patterns in large traffic datasets.…”
Section: Traffic On the As Topologymentioning
confidence: 99%
“…GÉANT, towards all destinations to which the observation network sends traffic. References [14,25,26] focus on the paths of the traffic observed by some network, but only the part that crosses that network. Our work is the first to try to characterize the space-time dynamics of traffic as seen by a large network provider as it crosses the whole Internet topology.…”
Section: Traffic On the As Topologymentioning
confidence: 99%
See 1 more Smart Citation
“…Techniques such as Principal Component Analysis and Independent Component Analysis have been used to identify and retain independent variables and remove the redundant and derived metrics [14]. Data compression techniques have also been used to define the purging and retention policies [15].…”
Section: Related Workmentioning
confidence: 99%
“…Our algorithm is derived from the technique developed in Lakhina et al [16] for wired infrastructure networks. The method of Lakhina et al [16] employs Principal Component Analysis (PCA) [13] for dimension reduction and filtering of observed data and uses Hotelling's t 2 statistics to detect the data points deviating far from the mean traffic conditions. We have evaluated the scheme of Lakhina et al [16] in Hakami et al [8] for the scenario of a WMN testbed deployed in Sydney.…”
Section: Introductionmentioning
confidence: 99%