Please use this identifier to cite or link to this item:
https://repository.cihe.edu.hk/jspui/handle/cihe/1944
Title: | Entropy based adaptive flow aggregation | Author(s): | Chiu, Dah Ming | Author(s): | Hu, Y. Lui, J. C. S. |
Issue Date: | 2009 | Publisher: | IEEE | Journal: | IEEE/ACM Transactions on Networking | Volume: | 17 | Issue: | 3 | Start page: | 698 | End page: | 711 | Abstract: | Internet traffic flow measurement is vitally important for network management, accounting and performance studies. Cisco's NetFlow is a widely deployed flow measurement solution that uses a configurable static sampling rate to control processor and memory usage on the router and the amount of reporting flow records generated. But during flooding attacks the memory and network bandwidth consumed by flow records can increase beyond what is available. Currently available countermeasures have their own problems: 1) reject new flows when the cache is full - some legitimate new flows will not be counted; 2) export not-terminated flows to make room for new ones - this will exhaust the export bandwidth; and 3) adapt the sampling rate to traffic rate - this will reduce the overall accuracy of accounting, including legitimate flows. In this paper, we propose an entropy based adaptive flow aggregation algorithm. Relying on information-theoretic techniques, the algorithm efficiently identifies the clusters of attack flows in real time and aggregates those large number of short attack flows into a few metaflows. Compared to currently available solutions, our solution not only alleviates the problem in memory and export bandwidth, but also significantly improves the accuracy of legitimate flows. Finally, we evaluate our system using both synthetic trace file and real trace files from the Internet. |
URI: | https://repository.cihe.edu.hk/jspui/handle/cihe/1944 | DOI: | 10.1109/TNET.2008.2002560 | CIHE Affiliated Publication: | No |
Appears in Collections: | SS Publication |
Show full item record
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.