On the Use of TCP Passive Measurements for Anomaly Detection: A Case Study from an Operational 3G Network

被引:0
|
作者
Romirer-Maierhofer, Peter
Coluccia, Angelo
Witek, Tobias
机构
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this work we discuss the use of passive measurements of TCP performance indicators in support of network operation and troubleshooting, presenting a case-study from a real 3G cellular network. From the analysis of TCP handshaking packets measured in the core network we infer Round-Trip-Times (RTT) on both the client and server sides separately for UMTS/HSPA. and GPRS/EDGE sections. We also keep track of the relative share of packet pairs which did not lead to a valid RTT sample, e.g. due to loss and/or retransmission events, and use this metric as an additional performance signal. In a previous work we identified the risk of measurement bias due to early retransmission of TCP SYNACK packets by some popular servers. In order to mitigate this problem we introduce here a novel algorithm for dynamic classification and filtering of early retransmitters. We present a few illustrative cases of abrupt-change observed in the real network, based on which we derive some lessons learned about using such data for detecting anomalies in a real network. Thanks to such measurements we were able to discover a hidden congestion bottleneck in the network under study.
引用
收藏
页码:183 / 197
页数:15
相关论文
共 50 条
  • [21] 3G network coverage hole detection based on user behaviors
    Long, Teng, 1600, Editorial Board of Journal on Communications (35):
  • [22] Recurrent Neural Network-based Prediction of TCP Transmission States from Passive Measurements
    Hagos, Desta Haileselassie
    Engelstad, Paal E.
    Yazidi, Anis
    Kure, Oivind
    2018 IEEE 17TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2018,
  • [23] Study on Simulation Technology of 3G Mobile Communication Network
    Zhu Li-zhong
    Yao Zheng-lin
    Guo Hai-feng
    PROCEEDINGS OF THE 2009 WRI GLOBAL CONGRESS ON INTELLIGENT SYSTEMS, VOL III, 2009, : 236 - +
  • [25] Network Planning Study of the metro optical network oriented 3G Application
    Gong, Q
    Xu, R
    Lin, JT
    Network Architectures, Management, and Applications II, Pts 1 and 2, 2005, 5626 : 659 - 668
  • [26] System-level Channel Modeling based on Active Measurements from a Public 3G/UMTS Network
    Yin, Xuefeng
    Zhang, Nan
    Zhong, Zhimeng
    Yu, Jiwei
    Tian, Li
    Zhang, Xiaomei
    Duan, Weiming
    2013 IEEE 78TH VEHICULAR TECHNOLOGY CONFERENCE (VTC FALL), 2013,
  • [27] Automation of network anomaly detection and mitigation with the use of IBN: A deployment case on KOREN
    Diaz Rivera, Javier Jose
    Khan, Talha Ahmed
    Akbar, Waleed
    Muhammad, Afaq
    Mehmood, Asif
    Song, Wang-Cheol
    2022 IEEE 23RD INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM 2022), 2022, : 294 - 299
  • [28] Characterization of a 3G EV-DO Network - a Measurement Study
    Zhou, Zhe
    Claypool, Mark
    Kinicki, Robert
    PROCEEDINGS OF THE 37TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS WORKSHOPS (LCN 2012), 2012, : 790 - 798
  • [29] Marrying Graph Kernel with Deep Neural Network: A Case Study for Network Anomaly Detection
    Yao, Yepeng
    Su, Liya
    Zhang, Chen
    Lu, Zhigang
    Liu, Baoxu
    COMPUTATIONAL SCIENCE - ICCS 2019, PT II, 2019, 11537 : 102 - 115
  • [30] Performance study of link layer and MAC layer protocols to support TCP in 3G CDMA systems
    Lin, HT
    Das, SK
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2005, 4 (05) : 489 - 501