Please use this identifier to cite or link to this item: https://repository.cihe.edu.hk/jspui/handle/cihe/1944
Title: Entropy based adaptive flow aggregation
Author(s): Chiu, Dah Ming 
Author(s): Hu, Y.
Lui, J. C. S.
Issue Date: 2009
Publisher: IEEE
Journal: IEEE/ACM Transactions on Networking 
Volume: 17
Issue: 3
Start page: 698
End page: 711
Abstract: 
Internet traffic flow measurement is vitally important for network management, accounting and performance studies. Cisco's NetFlow is a widely deployed flow measurement solution that uses a configurable static sampling rate to control processor and memory usage on the router and the amount of reporting flow records generated. But during flooding attacks the memory and network bandwidth consumed by flow records can increase beyond what is available. Currently available countermeasures have their own problems: 1) reject new flows when the cache is full - some legitimate new flows will not be counted; 2) export not-terminated flows to make room for new ones - this will exhaust the export bandwidth; and 3) adapt the sampling rate to traffic rate - this will reduce the overall accuracy of accounting, including legitimate flows. In this paper, we propose an entropy based adaptive flow aggregation algorithm. Relying on information-theoretic techniques, the algorithm efficiently identifies the clusters of attack flows in real time and aggregates those large number of short attack flows into a few metaflows. Compared to currently available solutions, our solution not only alleviates the problem in memory and export bandwidth, but also significantly improves the accuracy of legitimate flows. Finally, we evaluate our system using both synthetic trace file and real trace files from the Internet.
URI: https://repository.cihe.edu.hk/jspui/handle/cihe/1944
DOI: 10.1109/TNET.2008.2002560
CIHE Affiliated Publication: No
Appears in Collections:SS Publication

SFX Query Show full item record

Google ScholarTM

Check

Altmetric

Altmetric


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.