Back to Search
Start Over
Remote detection of bottleneck links using spectral and statistical methods
- Source :
- Computer Networks. 53:279-298
- Publication Year :
- 2009
- Publisher :
- Elsevier BV, 2009.
-
Abstract
- Persistently saturated links are abnormal conditions that indicate bottlenecks in Internet traffic. Network operators are interested in detecting such links for troubleshooting, to improve capacity planning and traffic estimation, and to detect denial-of-service attacks. Currently bottleneck links can be detected either locally, through SNMP information, or remotely, through active probing or passive flow-based analysis. However, local SNMP information may not be available due to administrative restrictions, and existing remote approaches are not used systematically because of their network or computation overhead. This paper proposes a new approach to remotely detect the presence of bottleneck links using spectral and statistical analysis of traffic. Our approach is passive, operates on aggregate traffic without flow separation, and supports remote detection of bottlenecks, addressing some of the major limitations of existing approaches. Our technique assumes that traffic through the bottleneck is dominated by packets with a common size (typically the maximum transfer unit, for reasons discussed in Section 5.1). With this assumption, we observe that bottlenecks imprint periodicities on packet transmissions based on the packet size and link bandwidth. Such periodicities manifest themselves as strong frequencies in the spectral representation of the aggregate traffic observed at a downstream monitoring point. We propose a detection algorithm based on rigorous statistical methods to detect the presence of bottleneck links by examining strong frequencies in aggregate traffic. We use data from live Internet traces to evaluate the performance of our algorithm under various network conditions. Results show that with proper parameters our algorithm can provide excellent accuracy (up to 95%) even if the traffic through the bottleneck link accounts for less than 10% of the aggregate traffic.
- Subjects :
- Traffic analysis
Computer Networks and Communications
Computer science
Network packet
business.industry
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS
Real-time computing
Internet traffic
Simple Network Management Protocol
Traffic flow
Computer security
computer.software_genre
Bottleneck
Traffic flow (computer networking)
Network management
Capacity planning
Packet switching
Overhead (computing)
business
computer
Subjects
Details
- ISSN :
- 13891286
- Volume :
- 53
- Database :
- OpenAIRE
- Journal :
- Computer Networks
- Accession number :
- edsair.doi...........a05aeb096e04da35fafca046e309c617
- Full Text :
- https://doi.org/10.1016/j.comnet.2008.10.001