vix.ing · top · new · best · stats · spec

Mining Network Events using Traceroute Empathy

2014/12/12 by Marco Di Bartolomeo, Di Bartolomeo, Marco, Valentino Di Donato +7
Computer Science · Physics and Astronomy · #Anomaly Detection Techniques and Applications #Complex Network Analysis Techniques #FOS: Computer and information sciences #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI)

paper · pdf · doi:10.48550/arxiv.1412.4074

openalex publication_date 2014/12/12 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

In the never-ending quest for tools that enable an ISP to smooth troubleshooting and improve awareness of network behavior, very much effort has been devoted in the collection of data by active and passive measurement at the data plane and at the control plane level. Exploitation of collected data has been mostly focused on anomaly detection and on root-cause analysis. Our objective is somewhat in the middle. We consider traceroutes collected by a network of probes and aim at introducing a practically applicable methodology to quickly spot measurements that are related to high-impact events happened in the network. Such filtering process eases further in- depth human-based analysis, for example with visual tools which are effective only when handling a limited amount of data. We introduce the empathy relation between traceroutes as the cornerstone of our formal characterization of the traceroutes related to a network event. Based on this model, we describe an algorithm that finds traceroutes related to high-impact events in an arbitrary set of measurements. Evidence of the effectiveness of our approach is given by experimental results produced on real-world data.

Related