Fast traffic anomalies detection using SNMP MIB correlation analysis

  • Authors:
  • Dong Cheul Lee;Byungjoo Park;Ki Eung Kim;Jae Jin Lee

  • Affiliations:
  • Network Technology Laboratory, KT;Network Technology Laboratory, KT;Network Technology Laboratory, KT;Network Technology Laboratory, KT

  • Venue:
  • ICACT'09 Proceedings of the 11th international conference on Advanced Communication Technology - Volume 1
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Internet Service Providers(ISPs) should detect and control abnormal traffic fast for stable network management. One of the ways to detect traffic anomalies fast is shortening traffic collecting cycle. However, performance degradation is inevitable if a centralized traffic collection server gathers all traffic data from equipments in a large ISP. This paper presents an enhanced traffic collection algorithm that can gather traffic data frequently without degrading the performance by analyzing SNMP MID objects' correlation. The algorithm estimates the values of interface group objects by using ip group objects, thus, it reduces the number of collections. We evaluated this algorithm on KORNET backbone network. The performance degradation was not found on the experiment, and the accuracy of the algorithm was fairly good.