Skip to main navigation Skip to search Skip to main content

NEPnet: A scalable monitoring system for anomaly detection of network service

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Anomaly detection is very important for modern network service. Yet it is still a big challenge to conduct effective anomaly detection due to the high rate of service data and the complex correlations among them. Owing to the powerful query language and performance potential, complex event processing (CEP) is very suitable for this situation. In this paper, we present NEPnet, a high-performance and scalable monitoring system, which can process events for anomaly detection of network service in real time. NEPnet is based on CEP and provides a SQL-like language supporting various event correlations. On accepting pre-defined queries as input, NEPnet builds a tree-based monitoring net for detailed anomaly detection. Considering the anomaly features of network service, the monitoring net utilizes limit trigger, predicate index and route table for different types of processing nodes in it. Our preliminary experiment results show that NEPnet can effectively detect anomaly of network service, with a high-speed of 100,000 events per second and 3∼6 times faster than Esper, a general CEP engine.

Original languageEnglish
Title of host publication2011 7th International Conference on Network and Service Management, CNSM 2011
StatePublished - 2011
Event2011 7th International Conference on Network and Service Management, CNSM 2011 - Paris, France
Duration: 24 Oct 201128 Oct 2011

Publication series

Name2011 7th International Conference on Network and Service Management, CNSM 2011

Conference

Conference2011 7th International Conference on Network and Service Management, CNSM 2011
Country/TerritoryFrance
CityParis
Period24/10/1128/10/11

Keywords

  • anomaly detection
  • complex event processing
  • monitoring net
  • network service

Fingerprint

Dive into the research topics of 'NEPnet: A scalable monitoring system for anomaly detection of network service'. Together they form a unique fingerprint.

Cite this