skip to main content
article

Combining routing and traffic data for detection of IP forwarding anomalies

Published:01 June 2004Publication History
Skip Abstract Section

Abstract

IP forwarding anomalies, triggered by equipment failures, implementation bugs, or configuration errors, can significantly disrupt and degrade network service. Robust and reliable detection of such anomalies is essential to rapid problem diagnosis, problem mitigation, and repair. We propose a simple, robust method that integrates routing and traffic data streams to reliably detect forwarding anomalies. The overall method is scalable, automated and self-training. We find this technique effectively identifies forwarding anomalies, while avoiding the high false alarms rate that would otherwise result if either stream were used unilaterally.

References

  1. A.Brown and D. A. Patterson, "To err is human," in Proceedings of the First Workshop on Evaluating and Architecting System dependability (EASY'01), (Göteborg, Sweden), 2001.Google ScholarGoogle Scholar
  2. D. Patterson, A. Brown, P. Broadwell, G. Candea, M. Chen, J. Cutler, P. Enriquez, A. Fox, E. Kiciman, M. Merzbacher, D. Oppenheimer, N. Sastry, W. Tetzlaff, J. Traupman, and N. Treuhaft, "Recovery-oriented computing (roc): Motivation, definition, techniques, and case studies," Tech. Rep. UCB//CSD-02-1175, UC Berkeley Computer Science, 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. D. Oppenheimer, A. Ganapathi, and D. A. Patterson, "Why do Internet services fail, and what can be done about it?," in 4th Usenix Symposium on Internet Technologies and Systems (USITS'03), 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. D.J.Houck, K.S.Meier-Hellstern, F.Saheban, and R.A.Skoog, "Failure and congestion propagation through signalling control," in Proceedings of the 14th International Teletraffic Congress (ITC-14) (J. Labetoulle and J. W.Roberts, eds.), vol. 1a, pp. 367--376, Elsevier, 1994.Google ScholarGoogle Scholar
  5. J. Strand, A. Chiu, and R. Tkach, "Issues for routing in the optical layer," IEEE Communications Magazine, February 2001. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. Nanog mailing list http://www.cctec.com/maillists/nanog/historical/0005/msg00073.html, 5th May 2000.Google ScholarGoogle Scholar
  7. Nanog mailing list: http://www.cctec.com/maillists/nanog/historical/0210/msg00058.html, 3rd October 2002.Google ScholarGoogle Scholar
  8. J. D. Brutag, "Aberrant behavior detection and control in time series for network monitoring," in Proceedings of the 14th Systems Administration Conference (LISA 2000), (New Orleans, LA, USA), USENIX, December 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. M. Roughan, A. Greenberg, C. Kalmanek, M. Rumsewicz, J. Yates, and Y. Zhang, "Experience in measuring Internet backbone traffic variability: Models, metrics, measurements and meaning," in Proceedings of the International Teletraffic Congress (ITC-18), 2003.Google ScholarGoogle Scholar
  10. S. H. Steiner, "Grouped data exponentially weighted moving average control charts," Applied Statistics, vol. 47, no. 2, 1998.Google ScholarGoogle Scholar
  11. P. Barford, J. Kline, D. Plonka, and A. Ron, "A signal analysis of network traffic anomalies," in ACM SIGCOMM Internet Measurement Workshop, (Marseilles, France), November 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Combining routing and traffic data for detection of IP forwarding anomalies

            Recommendations

            Comments

            Login options

            Check if you have access through your login credentials or your institution to get full access on this article.

            Sign in

            Full Access

            • Published in

              cover image ACM SIGMETRICS Performance Evaluation Review
              ACM SIGMETRICS Performance Evaluation Review  Volume 32, Issue 1
              June 2004
              432 pages
              ISSN:0163-5999
              DOI:10.1145/1012888
              Issue’s Table of Contents
              • cover image ACM Conferences
                SIGMETRICS '04/Performance '04: Proceedings of the joint international conference on Measurement and modeling of computer systems
                June 2004
                450 pages
                ISBN:1581138733
                DOI:10.1145/1005686

              Copyright © 2004 ACM

              Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

              Publisher

              Association for Computing Machinery

              New York, NY, United States

              Publication History

              • Published: 1 June 2004

              Check for updates

              Qualifiers

              • article

            PDF Format

            View or Download as a PDF file.

            PDF

            eReader

            View online with eReader.

            eReader