Detection of anomalous network behavior based on one-way delay measurements
摘要
A global network monitoring system measuring IP network performance metrics (IPPM) is presented, which is proposed for use in network security. The monitoring system measures network latency and related values. The dependence of IPPM on the power of a DDoS attack is used to determine the moment of the attack. Another method of attack detection is to study changes in routes between measurement nodes. A change in route is accompanied by a sudden change in one-way delay (OWD). Recent reviews on OWD recommend the use of the One-way Active Measurement Protocol (OWAMP protocol). Studies have shown that using the OWAMP protocol to measure OWD gives two different results for the same route. An updated mechanism for measuring one-way delay has been proposed. The novelty of the method lies in the use of a new type of timestamp, which is set directly at the moment of sending and receiving the measurement packet. A new measurement utility has been created that eliminates measurement errors.