インターネットと運用技術シンポジウム 2016 Internet and Operation Technology Symposium 2016 IOTS /12/1 syslog 1,2,a) 3,b) syslog syslog syslog Interop Tokyo Show

Similar documents
untitled

2. Twitter Twitter 2.1 Twitter Twitter( ) Twitter Twitter ( 1 ) RT ReTweet RT ReTweet RT ( 2 ) URL Twitter Twitter 140 URL URL URL 140 URL URL

untitled

untitled

IPSJ SIG Technical Report Vol.2014-DBS-159 No.6 Vol.2014-IFAT-115 No /8/1 1,a) 1 1 1,, 1. ([1]) ([2], [3]) A B 1 ([4]) 1 Graduate School of Info

AV 1000 BASE-T LAN 90 IEEE ac USB (3 ) LAN (IEEE 802.1X ) LAN AWS (Amazon Web Services) AP 3 USB wget iperf3 wget 40 MBytes 2 wget 40 MByt

March

AP_12_15_yonezawa.indd

Dual Stack Virtual Network Dual Stack Network RS DC Real Network 一般端末 GN NTM 端末 C NTM 端末 B IPv4 Private Network IPv4 Global Network NTM 端末 A NTM 端末 B

459

nakayama15icm01_l7filter.pptx

2 3

IPSJ SIG Technical Report Vol.2011-IOT-12 No /3/ , 6 Construction and Operation of Large Scale Web Contents Distribution Platfo

22 Google Trends Estimation of Stock Dealing Timing using Google Trends

帯域を測ってみよう (適応型QoS/QoS連携/帯域検出機能)

Web Web Web Web Web, i

【HP用】26.12月号indd.indd

26.2月号indd.indd

26.1月号indd.indd

OSPF OSPF.

THE INSTITUTE OF ELECTRONICS, INFORMATION AND COMMUNICATION ENGINEERS TECHNICAL REPORT OF IEICE.


1 2

29 Short-time prediction of time series data for binary option trade

"CAS を利用した Single Sign On 環境の構築"

1. [5] Wikipedia 4. ( ) Wikipedia 5. 3 ( ) ( ) ( ) Wikipedia ( ) ( ) 2.2 Global Database of Events, Language and Tone (GDELT) Global Datab

Vol. 42 No pp Headcount ratio p p A B pp.29

28 NTMobile Java Proposal and Implementation of Java Wrapper for NTMobile ( : ) :

I TCP 1/2 1


人工知能学会研究会資料 SIG-KBS-B Analysis of Voting Behavior in One Night Werewolf 1 2 Ema Nishizaki 1 Tomonobu Ozaki Graduate School of Integrated B

2.R R R R Pan-Tompkins(PT) [8] R 2 SQRS[9] PT Q R WQRS[10] Quad Level Vector(QLV)[11] QRS R Continuous Wavelet Transform(CWT)[12] Mexican hat 4

UsersGuide_INR-HG5497c_.doc

MMXVC_H1

30

ビッグデータアナリティクス - 第3回: 分散処理とApache Spark

25 About what prevent spoofing of misusing a session information

ア 接続 管理 ーバ ー GPS インター ッ S C バス位置情報 バス ー ータ ー バス運行情報 & ニ ース 1 S バス停 ー C コンセン ータ CATV/FTTH GPS Web 2.2 Linux GPS Linux GPS c 2015 Infor

Stepwise Chow Test * Chow Test Chow Test Stepwise Chow Test Stepwise Chow Test Stepwise Chow Test Riddell Riddell first step second step sub-step Step

00hyoshi

"CAS を利用した Single Sign On 環境の構築"

IP 2.2 (IP ) IP 2.3 DNS IP IP DNS DNS 3 (PC) PC PC PC Linux(ubuntu) PC TA 2

Run-Based Trieから構成される 決定木の枝刈り法

1 [1, 2, 3, 4, 5, 8, 9, 10, 12, 15] The Boston Public Schools system, BPS (Deferred Acceptance system, DA) (Top Trading Cycles system, TTC) cf. [13] [

LAN LAN LAN LAN LAN LAN,, i

DEIM Forum 2017 H ,

DEIM Forum 2019 H2-2 SuperSQL SuperSQL SQL SuperSQL Web SuperSQL DBMS Pi

GET Vol.8

IEEE e

IPSJ SIG Technical Report Vol.2016-CE-137 No /12/ e β /α α β β / α A judgment method of difficulty of task for a learner using simple

,,.,.,,.,.,.,.,,.,..,,,, i

DEIM Forum 2009 C8-4 QA NTT QA QA QA 2 QA Abstract Questions Recomme

showNet2013.indd

_‚Ofl¼

,…I…y…„†[…e…B…fi…O…V…X…e…•‡Ì…J†[…l…‰fi®“ì‡Ì›Â”‰›»pdfauthor

Input image Initialize variables Loop for period of oscillation Update height map Make shade image Change property of image Output image Change time L

DPA,, ShareLog 3) 4) 2.2 Strino Strino STRain-based user Interface with tacticle of elastic Natural ObjectsStrino 1 Strino ) PC Log-Log (2007 6)

Duplicate Near Duplicate Intact Partial Copy Original Image Near Partial Copy Near Partial Copy with a background (a) (b) 2 1 [6] SIFT SIFT SIF

258 5) GPS 1 GPS 6) GPS DP 7) 8) 10) GPS GPS ) GPS Global Positioning System

1 1 CodeDrummer CodeMusician CodeDrummer Fig. 1 Overview of proposal system c

Libraion20.indd

1,.,., Unicode,.,,.,. 2010,,,.,,.

1.0, λ. Holt-Winters t + h,ỹ t ỹ t+h t = ỹ t + hf t.,,.,,,., Hassan [5],,,.,,,,,,Hassan EM,, [6] [8].,,,,Stenger [9]. Baum-Welch, Baum-Welch (Incremen

IPSJ SIG Technical Report Vol.2014-IOT-27 No.14 Vol.2014-SPT-11 No /10/10 1,a) 2 zabbix Consideration of a system to support understanding of f

IPv4aaSを実現する技術の紹介

P3FY-A JP.PDF

Ubuntu Linux PC Ubuntu Linux (14.04 LTS, Trusty Tahr) 32bit CD 64bit CD 2. 32bit CPU 64bit 32bit PC CPU 32bit 64bit Windows 64bit 64bit. 32bit Core 64

k2 ( :35 ) ( k2) (GLM) web web 1 :

LSM-L3-24設定ガイド(初版)

kubostat2015e p.2 how to specify Poisson regression model, a GLM GLM how to specify model, a GLM GLM logistic probability distribution Poisson distrib


i


(1) 2


1 Fig. 1 Extraction of motion,.,,, 4,,, 3., 1, 2. 2.,. CHLAC,. 2.1,. (256 ).,., CHLAC. CHLAC, HLAC. 2.3 (HLAC ) r,.,. HLAC. N. 2 HLAC Fig. 2

4. C i k = 2 k-means C 1 i, C 2 i 5. C i x i p [ f(θ i ; x) = (2π) p 2 Vi 1 2 exp (x µ ] i) t V 1 i (x µ i ) 2 BIC BIC = 2 log L( ˆθ i ; x i C i ) + q

DEIM Forum 2017 E Netflix (Video on Demand) IP 4K [1] Video on D

RT-PCR プロトコール.PDF

97-00


2

owners.book

high collar

表1-表4宅建99.indd

表1-表4宅建98.indd

表1-表4宅建101.indd

表1-表4宅建いわて-表紙.indd

Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi


PDF

1. 1 DBMS Unix (USP ) ( )[3] 20 UNIX [2] KISS UNIX 1. 2 (Tukubai ) Unix OS Unix USP Tukubai Tukubai 1. 3 Unix SQL Tukubai usp Tukubai Open usp Tukubai

2011 I/ 2 1

SERPWatcher SERPWatcher SERP Watcher SERP Watcher,

The 15th Game Programming Workshop 2010 Magic Bitboard Magic Bitboard Bitboard Magic Bitboard Bitboard Magic Bitboard Magic Bitboard Magic Bitbo

IT i

RTX830 取扱説明書

PDA 8) ID ZigBee 10) 7) 12) 10) 11) ( 1) Bluetooth Bluetooth Bluetooth 9) WiFi WiFi NTP (X,Y,Z 3 ) ZigBee 10) Fig. 1 1 Overview of recording, analyzin

"CAS を利用した Single Sign On 環境の構築"

ECCS. ECCS,. ( 2. Mac Do-file Editor. Mac Do-file Editor Windows Do-file Editor Top Do-file e

Transcription:

syslog 1,2,a) 3,b) syslog syslog syslog Interop Tokyo ShowNet syslog Proposal of the anomaly detection method analyzing syslog data using Bollinger Bands algorithm on event network Hiroshi Abe 1,2,a) Mikifumi Shikida 3,b) 1. 1.1 1 2 / 1 IIJ 2 3 a) abe@iij.ad.jp/h-abe@jaist.ac.jp b) shikida.mikifumi@kochi-tech.ac.jp / / syslog syslog 57

1 VMware vrealize LogInsight syslog Interop Tokyo[1] ShowNet[2] syslog 1.2 ShowNet ShowNet Interop Tokyo 2 ShowNet ShowNet ShowNet syslog ShowNet 1.3 ShowNet syslog ShowNet 1 syslog 1 VMware vrealize LogInsight [3](LogInsight) syslog LogInsight, (OSPF down/bgp down/storm detection ) ( ) ShowNet debug info ShowNet syslog 1.4 2, 3 4, 5. 6 7 2. Holt-Winters [4] ShowNet Jon Kleinberg [5] Kleinberg 58

syslog ChangeFinder[6] ChangeFinder. Google word2vec[7]. syslog 3. 3.1 ShowNet syslog ShowNet syslog [8] 3.2 1 1980 John Bollinger 2 2 ( ) 68.26% 2 ( ) 95.44% 3 ( ) 99.73% 95.44% 2 +2-2 + 2 ( ) UpperLimit() - 2 ( ) LowerLimit() () x = 1 n n 1 x i i=0 ( ) σ = 1 n 1 (x i x) 2 n i=0 59

OS CentOS 7.2 1 Python 3.5.1 CPU Intel(R) Xeon(R) CPU E5-2670 v3 @ 2.30GHz 128GB { n 1 = 1 n 2 n x 2 i i=0 ( n 1 ) 2 } x i i=0 ( ) 2 UpperLimit, LowerLimit 3.3 syslog syslog 2 ( ) syslog ( 2 ) 95.44% UpperLimit LowerLimit 4.56% 4.56% 4. 4.1 1 ShowNet ShowNet Python syslog 6.4GB 4,350 4.2. syslog. syslog [9] Mmm dd hh:mm:ss IP 1 import pandas as pd 2 df = pd. read_csv (./2016-06 -06 - syslog. log, delim_whitespace =True,...) 3 count = df. groupby (pd. TimeGrouper ( 1 Min )). count () 4 mean = count. rolling ( window =60). mean () 5 std = count. rolling ( window =60). std () 6 std_plus = std. apply ( lambda x: x * 2) 7 std_ minus = std. apply ( lambda x: x * -2) 8 upper_ limit = mean. add ( std_plus ) 9 lower_limit = mean. add ( std_minus ) 3 2 csv csv Python pandas[10] csv pandas DataFrame DataFrame pandas 1 1 DataFrame DataFrame ( : mean : std ) 1 / 1 1 (0 23 ) 1 / 1 60 3 1) pandas 2) (csv ) 3) DataFrame 1 4) mean 5) std 6) 2 (+2 ) 60

4 1 2 Level Low 1-100 Middle 100-1000 High 1000 3 5/27 192 617 34 5.51% 5/28 181,285 1440 111 7.71% 5/29 552,579 1440 96 6.67% 5/30 821,363 1440 88 6.11% 5/31 617,368 1440 71 4.93% 6/1 917,368 1440 82 5.69% 6/2 1,949,738 1440 91 6.32% 6/3 1,771,956 1440 69 4.79% 6/4 2,108,661 1440 75 5.21% 6/5 3,177,122 1440 71 4.93% 6/6 3,297,654 1440 51 3.54% 6/7 2,702,382 1440 67 4.65% 6/8 3,186,363 1440 87 6.04% 6/9 12,769,834 1440 65 4.51% 6/10 9,446,694 1083 65 6.00% 43,500,499 20420 1123 5.50% 7) -2 (-2 ) 8) (UpperLimit) 9) (LowerLimit) 5/27 4 count 1 Upper- Limit LowerLimit UpperLimit LowerLimit +2 UpperLimit UpperLimit +2 2.28% UpperLimit syslog DoS(Denial of Service). +2 ( 2) Low, Middle, High 3 +2 5. 5.1 ShowNet syslog 3 3 ( 1 ) ( 2 ) ( 3 ) ( 4 ) ( 5 ) 5 syslog (1 :60 ) 1 (86400 ) (86400/60=1440) 5/27 1440 1 192 syslog 5/27 syslog. ShowNet syslog. 6/10 1440 17 ShowNet UpperLimit UpperLimit ShowNet 5.50% 94.5% UpperLimit ShowNet (Hotstage) 61

4 Low Middle High 5/27 34 34 0 0 5/28 111 86 25 0 5/29 96 30 64 2 5/30 88 30 42 16 5/31 71 30 30 11 6/1 82 32 38 12 6/2 91 27 39 25 6/3 69 38 23 8 6/4 75 26 38 11 6/5 71 25 39 7 6/6 51 15 22 14 6/7 67 28 36 3 6/8 87 24 57 6 6/9 65 25 39 1 6/10 65 19 35 11 1123 469 527 127 41.76% 46.93% 11.31% 5 6/6 3 Hotstage 5/27 6/3, 6/4 6/7, 6/8 6/10 Hotstage syslog ShowNet. 200 1,200 3% 6% 5.2 2 4 Low 41.76%, Middle 46.93%, High 11.31% Low Middle 88% 5.3 ShowNet High syslog 3 5.3.1 6/6 6/6 18 ( 5) +2 6 6/8 SNMP Get request is recieved. :... SNMP Get response is sent. :... SNMP Get request response 18:10-18:16 ShowNet OID SNMP Get 6/6 18:10-18:16 SNMP SNMP ACL SNMP SNMP Daemon 5.3.2 6/8 6/9 6/9 3 6/1 6/8 100 300 6/9 1,200 6/8 23 6 6/10 1 9,000 6/8 23 6/6 SNMP SNMP 62

7 6/9 94.5% UpperLimit 8 6/10 UpperLimit 6/8 High 6/9( 7) 6/9 1200 4.51% 5.3.3 6/10 8 6/10 8 ShowNet NFV(Network Functional Virtualization) BGP(Border Gateway Protocol) 5 High High 6. 6.1 5.1 ShowNet syslog +2 2.28% 6.2 5.2 Low Middle 88% High High 5.3 3 UpperLimit 6.3 syslog 6.4 ShowNet 5.3 63

2-3 ShowNet 2 1.. 6.5 ShowNet syslog 7. 7.1 ShowNet syslog +2 94.5% UpperLimit. UpperLimit LowerLimit syslog syslog [1] Interop Tokyo, http://www.interop.jp/ [2] ShowNet, http://www.interop.jp/2016/shownet/ [3] VMware vrealize Log Insight, http://www.vmware.com/jp/products/vrealize-loginsight.html [4] Kalekar, Prajakta S.: Time series forecasting using holtwinters exponential smoothing. Kanwal Rekhi School of Information Technology 4329008 (2004): 1-13. [5] Kleinberg,J.: Bursty and Hierarchical Structure in Streams,Proc,8th SIGKDD pp.91101,2002. [6] J. Takeuchi and K. Yamanishi : A Unifying Framework for Detecting Outliers and Change Points from Time Series, IEEE transactions on Knowledge and Data Engineering, vol.18, no.4, pp.482-492, 2006. [7] word2vec, https://github.com/dav/word2vec [8] Bollinger, J. : Bollinger on Bollinger Bands. McGraw Hill, 2002 [9] Gerhards, R : RFC 5424,The Syslog Protocol, March 2009, https://tools.ietf.org/html/rfc5424 [10] pandas, Python Data Analysis Library: http://pandas.pydata.org/ 7.2 ShowNet. ShowNet / 64