Home > Research > Publications & Outputs > Internet traffic characterisation

Links

Text available via DOI:

View graph of relations

Internet traffic characterisation: Third-order statistics & higher-order spectra for precise traffic modelling

Research output: Contribution to Journal/MagazineJournal articlepeer-review

Published

Standard

Internet traffic characterisation: Third-order statistics & higher-order spectra for precise traffic modelling. / Marnerides, Angelos; Pezaros, Dimitrios; Hutchison, David.
In: Computer Networks, Vol. 134, 07.04.2018, p. 183-201.

Research output: Contribution to Journal/MagazineJournal articlepeer-review

Harvard

APA

Vancouver

Marnerides A, Pezaros D, Hutchison D. Internet traffic characterisation: Third-order statistics & higher-order spectra for precise traffic modelling. Computer Networks. 2018 Apr 7;134:183-201. Epub 2018 Feb 7. doi: 10.1016/j.comnet.2018.01.050

Author

Bibtex

@article{0f31984c28294951b3ec993ebd6c972d,
title = "Internet traffic characterisation: Third-order statistics & higher-order spectra for precise traffic modelling",
abstract = "Undoubtedly, the characterisation of network traffic flows is vitally important in understanding the dynamics of Internet traffic and in appropriately dimensioning network resources for network and systems management. The vast majority of modelling techniques developed for volume-based traffic profiling (based on packet and/byte counts) imply the statistical assumptions of stationarity, Gaussianity and linearity, which are often taken for granted without being explicitly validated. In this paper, we demonstrate that such properties are often not applicable due to the high fluctuations in Internet traffic, and should therefore be validated first before they are assumed. We employ Time-Frequency (TF) representations and the Hinich algorithms for validating these three modelling assumptions on real backbone and edge network traces. We show by conducting a passive, offline statistical analysis on real operational network traffic traces from both backbone and edge links that link traffic is extremely dynamic irrespective of the level of aggregation and that model characteristics vary. Subsequently, we propose the use of a representative of higher order spectra, the bispectrum, to act as a particularly suitable method for volume-based traffic profiling due to its ability to adapt to different underlying statistical assumptions, as opposed to ARIMA timeseries models that have been typically used in the literature. We demonstrate that the bispectrum, a signal processing tool that has so far been used in the area of image processing and acoustic signals, can be exploited to accurately characterise traffic volumes per transport protocol, and can therefore contribute to fine-grained network operations tasks such as application classification and anomaly detection.",
keywords = "Internet traffic characterisation, Traffic engineering, Higher order spectra",
author = "Angelos Marnerides and Dimitrios Pezaros and David Hutchison",
year = "2018",
month = apr,
day = "7",
doi = "10.1016/j.comnet.2018.01.050",
language = "English",
volume = "134",
pages = "183--201",
journal = "Computer Networks",
issn = "1389-1286",
publisher = "ELSEVIER SCIENCE BV",

}

RIS

TY - JOUR

T1 - Internet traffic characterisation

T2 - Third-order statistics & higher-order spectra for precise traffic modelling

AU - Marnerides, Angelos

AU - Pezaros, Dimitrios

AU - Hutchison, David

PY - 2018/4/7

Y1 - 2018/4/7

N2 - Undoubtedly, the characterisation of network traffic flows is vitally important in understanding the dynamics of Internet traffic and in appropriately dimensioning network resources for network and systems management. The vast majority of modelling techniques developed for volume-based traffic profiling (based on packet and/byte counts) imply the statistical assumptions of stationarity, Gaussianity and linearity, which are often taken for granted without being explicitly validated. In this paper, we demonstrate that such properties are often not applicable due to the high fluctuations in Internet traffic, and should therefore be validated first before they are assumed. We employ Time-Frequency (TF) representations and the Hinich algorithms for validating these three modelling assumptions on real backbone and edge network traces. We show by conducting a passive, offline statistical analysis on real operational network traffic traces from both backbone and edge links that link traffic is extremely dynamic irrespective of the level of aggregation and that model characteristics vary. Subsequently, we propose the use of a representative of higher order spectra, the bispectrum, to act as a particularly suitable method for volume-based traffic profiling due to its ability to adapt to different underlying statistical assumptions, as opposed to ARIMA timeseries models that have been typically used in the literature. We demonstrate that the bispectrum, a signal processing tool that has so far been used in the area of image processing and acoustic signals, can be exploited to accurately characterise traffic volumes per transport protocol, and can therefore contribute to fine-grained network operations tasks such as application classification and anomaly detection.

AB - Undoubtedly, the characterisation of network traffic flows is vitally important in understanding the dynamics of Internet traffic and in appropriately dimensioning network resources for network and systems management. The vast majority of modelling techniques developed for volume-based traffic profiling (based on packet and/byte counts) imply the statistical assumptions of stationarity, Gaussianity and linearity, which are often taken for granted without being explicitly validated. In this paper, we demonstrate that such properties are often not applicable due to the high fluctuations in Internet traffic, and should therefore be validated first before they are assumed. We employ Time-Frequency (TF) representations and the Hinich algorithms for validating these three modelling assumptions on real backbone and edge network traces. We show by conducting a passive, offline statistical analysis on real operational network traffic traces from both backbone and edge links that link traffic is extremely dynamic irrespective of the level of aggregation and that model characteristics vary. Subsequently, we propose the use of a representative of higher order spectra, the bispectrum, to act as a particularly suitable method for volume-based traffic profiling due to its ability to adapt to different underlying statistical assumptions, as opposed to ARIMA timeseries models that have been typically used in the literature. We demonstrate that the bispectrum, a signal processing tool that has so far been used in the area of image processing and acoustic signals, can be exploited to accurately characterise traffic volumes per transport protocol, and can therefore contribute to fine-grained network operations tasks such as application classification and anomaly detection.

KW - Internet traffic characterisation

KW - Traffic engineering

KW - Higher order spectra

U2 - 10.1016/j.comnet.2018.01.050

DO - 10.1016/j.comnet.2018.01.050

M3 - Journal article

VL - 134

SP - 183

EP - 201

JO - Computer Networks

JF - Computer Networks

SN - 1389-1286

ER -