论文标题

Bigben:用于互联网活动监控的遥测处理

BigBen: Telemetry Processing for Internet-wide Event Monitoring

论文作者

Syamkumar, Meenakshi, Gullapalli, Yugali, Tang, Wei, Barford, Paul, Sommers, Joel

论文摘要

本文介绍了Bigben,这是一个网络遥测处理系统,旨在启用互联网事件的准确,及时报告(例如,停机,攻击和配置更改)。 Bigben在使用网络时间协议(NTP)流量的被动测量方面与其他Internet范围内的事件检测系统不同。我们描述了Bigben的体系结构,其中包括(i)分布式NTP流量收集组件,(ii)提取物转换负载(ETL)组件,(iii)事件识别组件,以及(iv)可视化和报告组件。我们还描述了开发的基于云的Bigben实现,以处理大型NTP数据集并提供日常事件报告。我们在NTP数据的15.5TB语料库中演示了Bigben。我们证明我们的实施是有效的,可以支持小时活动报告。我们表明,Bigben确定了各种以其位置,范围和持续时间为特征的互联网事件。我们比较了由大型基于探针的大型检测系统检测到的Bigben与事件检测到的事件。我们只发现谦虚的重叠,并显示Bigben如何提供有关活动测量结果无法获得的事件的详细信息。最后,我们报告了Bigben在第三方报告的互联网事件中提供的观点。在每种情况下,Bigben都确认了事件,并提供了先前报告中没有可用的详细信息,从而突出了被动,基于NTP的方法的实用性。

This paper describes BigBen, a network telemetry processing system designed to enable accurate and timely reporting of Internet events (e.g., outages, attacks and configuration changes). BigBen is distinct from other Internet-wide event detection systems in its use of passive measurements of Network Time Protocol (NTP) traffic. We describe the architecture of BigBen, which includes (i) a distributed NTP traffic collection component, (ii) an Extract Transform Load (ETL) component, (iii) an event identification component, and (iv) a visualization and reporting component. We also describe a cloud-based implementation of BigBen developed to process large NTP data sets and provide daily event reporting. We demonstrate BigBen on a 15.5TB corpus of NTP data. We show that our implementation is efficient and could support hourly event reporting. We show that BigBen identifies a wide range of Internet events characterized by their location, scope and duration. We compare the events detected by BigBen vs. events detected by a large active probe-based detection system. We find only modest overlap and show how BigBen provides details on events that are not available from active measurements. Finally, we report on the perspective that BigBen provides on Internet events that were reported by third parties. In each case, BigBen confirms the event and provides details that were not available in prior reports, highlighting the utility of the passive, NTP-based approach.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源