@inproceedings{c04b00ca1b0e4e9ba9c50a94b0d3011d,
title = "NEPnet: A scalable monitoring system for anomaly detection of network service",
abstract = "Anomaly detection is very important for modern network service. Yet it is still a big challenge to conduct effective anomaly detection due to the high rate of service data and the complex correlations among them. Owing to the powerful query language and performance potential, complex event processing (CEP) is very suitable for this situation. In this paper, we present NEPnet, a high-performance and scalable monitoring system, which can process events for anomaly detection of network service in real time. NEPnet is based on CEP and provides a SQL-like language supporting various event correlations. On accepting pre-defined queries as input, NEPnet builds a tree-based monitoring net for detailed anomaly detection. Considering the anomaly features of network service, the monitoring net utilizes limit trigger, predicate index and route table for different types of processing nodes in it. Our preliminary experiment results show that NEPnet can effectively detect anomaly of network service, with a high-speed of 100,000 events per second and 3∼6 times faster than Esper, a general CEP engine.",
keywords = "anomaly detection, complex event processing, monitoring net, network service",
author = "Sujun Cheng and Zhendong Cheng and Zhongzhi Luan and Depei Qian",
year = "2011",
language = "英语",
isbn = "9781457715884",
series = "2011 7th International Conference on Network and Service Management, CNSM 2011",
booktitle = "2011 7th International Conference on Network and Service Management, CNSM 2011",
note = "2011 7th International Conference on Network and Service Management, CNSM 2011 ; Conference date: 24-10-2011 Through 28-10-2011",
}