Sciweavers

BROADNETS
2006
IEEE

A Statistical Approach to Anomaly Detection in Interdomain Routing

14 years 5 months ago
A Statistical Approach to Anomaly Detection in Interdomain Routing
Abstract— A number of events such as hurricanes, earthquakes, power outages can cause large-scale failures in the Internet. These in turn cause anomalies in the interdomain routing process. The policy-based nature of Border Gateway protocol (BGP) further aggravates the effect of these anomalies causing severe, long lasting route fluctuations. In this work we propose an architecture for anomaly detection that can be implemented on individual routers. We use statistical pattern recognition techniques for extracting meaningful features from the BGP update message data. A time-series segmentation algorithm is then carried out on the feature traces to detect the onset of an instability event. The performance of the proposed algorithm is evaluated using real Internet trace data. We show that instabilities triggered by events like router mis-configurations, infrastructure failures and worm attacks can be detected with a false alarm rate as low as 0.0083 alarms per hour. We also show that ...
Shivani Deshpande, Marina Thottan, Tin Kam Ho, Bip
Added 10 Jun 2010
Updated 10 Jun 2010
Type Conference
Year 2006
Where BROADNETS
Authors Shivani Deshpande, Marina Thottan, Tin Kam Ho, Biplab Sikdar
Comments (0)