Multivariate network traffic analysis using clustered patterns
- Texas A & M Univ., Commerce, TX (United States)
- Lawrence Berkeley National Lab. (LBNL), Berkeley, CA (United States)
- Energy Sciences Network, Berkeley, CA (United States)
- Electronics and Telecommunications Research Inst., Daejon (Korea, Republic of)
Traffic analysis is a core element in network operations and management for various purposes including change detection, traffic prediction, and anomaly detection. In this paper, we introduce a new approach to online traffic analysis based on a pattern-based representation for high-level summarization of the traffic measurement data. Unlike the past online analysis techniques limited to a single variable to summarize (e.g., sketch), the focus of this study is on capturing the network state from the multivariate attributes under consideration. To this end, we employ clustering with its benefit of the aggregation of multidimensional variables. The clustered result represents the state of the network with regard to the monitored variables, which can also be compared with the observed patterns from previous time windows enabling intuitive analysis. Finally, we demonstrate the proposed method with two popular use cases, one for estimating state changes and the other for identifying anomalous states, to confirm its feasibility. Our extensive experimental results with public traces and collected monitoring measurements from ESnet traffic traces show that our pattern-based approach is effective for multivariate analysis of online network traffic with visual and quantitative tools.
- Research Organization:
- Lawrence Berkeley National Laboratory (LBNL), Berkeley, CA (United States)
- Sponsoring Organization:
- USDOE Office of Science (SC), Advanced Scientific Computing Research (ASCR) (SC-21)
- Grant/Contract Number:
- AC02-05CH11231
- OSTI ID:
- 1498687
- Journal Information:
- Computing: Archiv fuer Informatik und Numerik, Journal Name: Computing: Archiv fuer Informatik und Numerik Journal Issue: 4 Vol. 101; ISSN 0010-485X
- Publisher:
- Springer NatureCopyright Statement
- Country of Publication:
- United States
- Language:
- English
Similar Records
An approach to online network monitoring using clustered patterns
Peeking Network States with Clustered Patterns