On the Use of TCP Passive Measurements for Anomaly Detection: A Case Study from an Operational 3G Network

被引:0
|
作者
Romirer-Maierhofer, Peter
Coluccia, Angelo
Witek, Tobias
机构
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this work we discuss the use of passive measurements of TCP performance indicators in support of network operation and troubleshooting, presenting a case-study from a real 3G cellular network. From the analysis of TCP handshaking packets measured in the core network we infer Round-Trip-Times (RTT) on both the client and server sides separately for UMTS/HSPA. and GPRS/EDGE sections. We also keep track of the relative share of packet pairs which did not lead to a valid RTT sample, e.g. due to loss and/or retransmission events, and use this metric as an additional performance signal. In a previous work we identified the risk of measurement bias due to early retransmission of TCP SYNACK packets by some popular servers. In order to mitigate this problem we introduce here a novel algorithm for dynamic classification and filtering of early retransmitters. We present a few illustrative cases of abrupt-change observed in the real network, based on which we derive some lessons learned about using such data for detecting anomalies in a real network. Thanks to such measurements we were able to discover a hidden congestion bottleneck in the network under study.
引用
收藏
页码:183 / 197
页数:15
相关论文
共 50 条
  • [31] Detection and Tracking of Skype by Exploiting Cross Layer Information in a Live 3G Network
    Svoboda, Philipp
    Hyytiae, Esa
    Ricciato, Fabio
    Rupp, Markus
    Karner, Martin
    TRAFFIC MONITORING AND ANALYSIS: FIRST INTERNATIONAL WORKSHOP, TMA 2009, 2009, 5537 : 93 - +
  • [32] An Enhanced Capacity Model based on Network Measurements for a Multi-Service 3G System
    Parracho, Diogo
    Duarte, David
    Pinto, Iola
    Vieira, Pedro
    2019 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2019, : 203 - 208
  • [33] Distribution of 3G Services in Rural Town: Case Study of Bhutan
    Tshering, Dago
    Chaisricharoen, Roungsan
    Temdee, Punnarumol
    2012 TENTH INTERNATIONAL CONFERENCE ON ICT AND KNOWLEDGE ENGINEERING, 2012, : 135 - 139
  • [34] RawPower: Deep Learning based Anomaly Detection from Raw Network Traffic Measurements
    Marin, Gonzalo
    Casas, Pedro
    Capdehourat, German
    SIGCOMM'18: PROCEEDINGS OF THE ACM SIGCOMM 2018 CONFERENCE: POSTERS AND DEMOS, 2018, : 75 - 77
  • [35] A Longitudinal Measurement Study of TCP Performance and Behavior in 3G/4G Networks Over High Speed Rails
    Li, Li
    Xu, Ke
    Wang, Dan
    Peng, Chunyi
    Zheng, Kai
    Mijumbi, Rashid
    Xiao, Qingyang
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (04) : 2195 - 2208
  • [36] The study on scalable video codec video communication in 3G wireless network
    Liu, Donghua
    Sun, Tong
    International Journal of Advancements in Computing Technology, 2012, 4 (21) : 230 - 238
  • [37] Study on the Applications of 3G Technology in Network Teaching of PE in Higher Institutions
    Zhu, Yuxia
    Sun, Guomin
    Huang, Huaming
    Dai, Bing
    PROCEEDINGS OF THE 2010 CONFERENCE ON COMPUTER SCIENCE IN SPORTS, 2010, : 43 - 46
  • [38] Anomaly detection in high-dimensional network data streams: A case study
    Zhang, Ji
    Gao, Qigang
    Wang, Hai
    ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2008, : 251 - +
  • [39] A New Passive Microwave Tool for Operational Forest Fires Detection: A Case Study of Siberia in 2019
    Varotsos, Costas A.
    Krapivin, Vladimir F.
    Mkrtchyan, Ferdenant A.
    REMOTE SENSING, 2020, 12 (05)
  • [40] Use of the Hydraulic Model for the Operational Analysis of the Water Supply Network: A Case Study
    Kepa, Urszula
    WATER, 2021, 13 (03) : 1 - 15