Lightweight Hierarchical Network Traffic Clustering

نویسندگان

  • Abdulrahman Hijazi
  • Hajime Inoue
  • Anil Somayaji
چکیده

We summarize our work with ADHIC (Approximate Divisive HIerarchical Clusterer), a lightweight, online, divisive hierarchical clustering algorithm tailored to the domain of network traffic clustering. We then briefly describe our implementation of ADHIC, NetADHICT, which serves as a tool to system administrators. The key innovation is that it can identify and present a hierarchical decomposition of traffic based upon the learned structure of whole packets without prior knowledge of protocol structures. ADHIC needs only a small fraction of packets to generate the cluster decision tree, and the generated tree can be used to cluster packets at wire speeds. Our experiments show NetADHICT can appropriately segregate well-known protocols, cluster traffic of the same protocol together even if it is running on multiple ports, and segregate p2p traffic that uses non-standard ports. We believe that ADHIC and NetADHICT are a useful complement to critical applications used for performance analysis, identification of worms and flash crowds, and Denial-of-Service resistant bandwidth management. ]

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Hierarchical Clustering and Sampling Techniques for Network Monitoring

Network monitoring applications are used to monitor network traffic flows. Clustering techniques are used to extract network traffic patterns. Anomaly detection schemes are used to detect network attacks. Hierarchical and partitional clustering schemes are used to analyze network traffic data values. The hierarchical data analysis uses the structure and data values for the clustering process. T...

متن کامل

Echidna: Efficient Clustering of Hierarchical Data for Network Traffic Analysis

There is significant interest in the network management community about the need to improve existing techniques for clustering multi-variate network traffic flow records so that we can quickly infer underlying traffic patterns. In this paper we investigate the use of clustering techniques to identify interesting traffic patterns in an efficient manner. We develop a framework to deal with mixed ...

متن کامل

Clustering for Hierarchical Traffic Grooming in Large Scale Mesh WDM Networks

We present a clustering algorithm for hierarchical traffic grooming in large WDM networks. In hierarchical grooming, the network is decomposed into clusters, and one hub node in each cluster is responsible for grooming traffic from and to the cluster. Hierarchical grooming scales to large network sizes and facilitates the control and management of traffic and network resources. Yet determining ...

متن کامل

Cluster Based Anomaly Detection in Wireless LAN

Data mining methods have gained importance in addressing computer network security. Existing Rule based classification models for anomaly detection are ineffective in dealing with dynamic changes in intrusion patterns and characteristic. Unsupervised learning methods have been given a closer look for network anomaly detection. We investigate hierarchical clustering algorithm for anomaly detecti...

متن کامل

Traffic state estimation using hierarchical clustering and principal components analysis: a practical approach

Traffic state estimation and prediction are fundamental requirements for automatic control of urban road traffic with both adaptive traffic lights and variable message signs. For that, collecting of actual traffic data is necessary. This paper deals with the combined application of principal components analysis (PCA) and hierarchical cluster analysis (HCA) for the specification of the needed nu...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007